Junglewise Threat Intelligence

CVE-2025-9049: Nokri Job Board WordPress Theme privilege escalation in account permissions

CVE-2025-9049 · Severity: high · CVSS 8.8 · Published 2026-09-05

Executive brief

The Nokri Job Board WordPress Theme, a popular job listing plugin for WordPress, contains a security flaw that allows authenticated users with basic subscriber accounts to gain administrative control over other user accounts. An attacker with subscriber-level access can create new accounts with elevated employer permissions and then use those to modify email addresses of any user, including site administrators, enabling complete account takeover and site compromise.

Technical details

The vulnerability is a privilege escalation flaw caused by missing capability checks in the 'nokri_account_member_permissions' function. Authenticated attackers with Subscriber-level access (or above) can bypass authorization checks to create new Subscriber users and assign them employer account member permissions. These newly created accounts can then escalate privileges further by modifying email addresses of any user in the system, including administrators. This is a chained privilege escalation attack requiring initial authentication but no special preconditions beyond subscriber access. The vulnerability affects all versions up to and including 1.6.4.

Affected products

  • Nokri Job Board WordPress Theme up to and including 1.6.4

Timeline

  • 2025-09-05: disclosed

References