# CVE-2024-12824

## Summary

- **CVE ID:** CVE-2024-12824
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-620
- **Published:** Mar 1, 2025
- **Last Modified:** Mar 13, 2026

## Description

The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.2. This is due to the plugin not properly checking for an empty token value prior updating their details like password. This makes it possible for unauthenticated attackers to change arbitrary user's password, including administrators, and leverage that to gain access to their account.

## Affected Products

- scriptsbundle — Nokri – Job Board WordPress Theme (*)

## References

- [CNA](https://www.wordfence.com/threat-intel/vulnerabilities/id/60a7cce0-637f-49bd-aa4a-fd7023d99a64?source=cve)
- [CNA](https://themeforest.net/item/nokri-job-board-wordpress-theme/22677241)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 2.34%
- **EPSS Percentile:** 82.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._