CVE-2024-12824
The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.2. This is due to the plugin not properly checking for an empty token value prior updating their details like password. This makes it possible for unauthenticated attackers to change arbitrary user's password, including administrators, and leverage that to gain access to their account.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 2.34%
- CWE
- CWE-620
- Published
- 2025-03-01
- Last modified
- 2026-03-13
Affected products
- scriptsbundle Nokri – Job Board WordPress Theme
Weakness type
Related vulnerabilities
- CVE-2025-4322 — Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
- CVE-2024-20419 — A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth
- CVE-2025-1107 — Unverified password change vulnerability in Janto
- CVE-2024-33699 — The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers t
- CVE-2025-3603 — Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Password Update
- CVE-2024-12860 — CarSpot – Dealership Wordpress Classified Theme <= 2.4.3 - Unauthenticated Arbitrary Password Reset/Account Takeover
- CVE-2025-4558 — WormHole Tech GPM - Unverified Password Change
- CVE-2025-2253 — IMITHEMES Listing <= 3.3 - Unauthenticated Privilege Escalation via Unverified Password Reset