Authentication vulnerability in Nokri – Job Board WordPress Theme 1.6.3

A popular WordPress theme called “Nokri – Job Board” has a security issue that can allow someone to take control of another user’s account. This is because the theme does not properly check a user’s identity before allowing them to change their email address. This means that someone with at least “Subscriber” level access could change the email address of any user, even an administrator, and use that to reset their password and gain access to their account.

Detected in:

Nokri - Job Board WordPress Theme fixed vulnerable versions:
Nokri – Job Board WordPress Theme fixed vulnerable versions: >= * <= 1.6.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.