CVE-2026-66691
9.8scriptsbundle · Nokri
A critical broken access control vulnerability exists in the scriptsbundle Nokri WordPress theme, which allows unauthenticated attackers to manipulate password recovery mechanisms.
Executive summary
The Nokri WordPress theme is susceptible to a critical access control vulnerability that permits unauthenticated attackers to exploit the password recovery process.
Vulnerability
This is a weak password recovery mechanism (CWE-640) that allows unauthenticated remote attackers to bypass existing security controls, potentially leading to unauthorized password resets for arbitrary accounts.
Business impact
The CVSS score of 9.8 reflects the high risk associated with this vulnerability, as it allows attackers to compromise user accounts by subverting the password recovery process. This can lead to unauthorized access to sensitive user data, financial information, or administrative panels, resulting in significant operational and reputational harm.
Remediation
Immediate Action: Update the Nokri theme to version 1.6.7 or higher immediately to mitigate the risks associated with the broken password recovery mechanism.
Proactive Monitoring: Audit logs for frequent or failed password reset requests, which may indicate an attacker attempting to enumerate or exploit the recovery flow.
Compensating Controls: Implement additional authentication layers, such as Multi-Factor Authentication (MFA), to ensure that even if a password is reset, the attacker cannot gain access to the account.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Administrators must update the Nokri theme to version 1.6.7 as a matter of urgency. By closing this vulnerability, you prevent attackers from hijacking accounts via the password recovery mechanism and ensure the integrity of your site access controls.