CVE-2026-66691

9.8

scriptsbundle · Nokri

A critical broken access control vulnerability exists in the scriptsbundle Nokri WordPress theme, which allows unauthenticated attackers to manipulate password recovery mechanisms.

Executive summary

The Nokri WordPress theme is susceptible to a critical access control vulnerability that permits unauthenticated attackers to exploit the password recovery process.

Vulnerability

This is a weak password recovery mechanism (CWE-640) that allows unauthenticated remote attackers to bypass existing security controls, potentially leading to unauthorized password resets for arbitrary accounts.

Business impact

The CVSS score of 9.8 reflects the high risk associated with this vulnerability, as it allows attackers to compromise user accounts by subverting the password recovery process. This can lead to unauthorized access to sensitive user data, financial information, or administrative panels, resulting in significant operational and reputational harm.

Remediation

Immediate Action: Update the Nokri theme to version 1.6.7 or higher immediately to mitigate the risks associated with the broken password recovery mechanism.

Proactive Monitoring: Audit logs for frequent or failed password reset requests, which may indicate an attacker attempting to enumerate or exploit the recovery flow.

Compensating Controls: Implement additional authentication layers, such as Multi-Factor Authentication (MFA), to ensure that even if a password is reset, the attacker cannot gain access to the account.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Administrators must update the Nokri theme to version 1.6.7 as a matter of urgency. By closing this vulnerability, you prevent attackers from hijacking accounts via the password recovery mechanism and ensure the integrity of your site access controls.