S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2025

CVE-2024-12824 Scanner

CVE-2024-12824 Scanner - Unauthenticated Arbitrary Password Change vulnerability in Nokri – Job Board WordPress Theme

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-12824
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.2. This is due to the plugin not properly checking for an empty token value prior updating their details like password. This makes it possible for unauthenticated attackers to change arbitrary user's password, including administrators, and leverage that to gain access to their account.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Nokri – Job Board WordPress Themeby scriptsbundle
0
Updated Aug 22, 2026View on NVD →
Detail

Nokri – Job Board is a WordPress theme designed for recruitment and employment purposes. It is frequently used by companies, recruitment agencies, and individuals looking to build job listing websites. The platform allows employers to post jobs, and potential employees to apply online. It is feature-rich, offering functionalities such as resume builder, paid job listings, career counseling, and more. This theme aims to simplify the process of connecting employers with employees. Its application is straightforward, making it accessible even to those with minimal technical knowledge.

This scanner detects a critical security vulnerability where unauthorized users can change passwords, including those of administrators in the Nokri – Job Board WordPress Theme. The vulnerability is due to improper verification of empty token values during password reset operations. This flaw allows attackers to escalate their privileges by taking over accounts. Such vulnerabilities could lead to significant security breaches if not addressed. It is crucial to detect and patch this vulnerability to maintain the integrity of the job board operations.

The technical aspect of this vulnerability involves the lack of adequate checks for token validation in the password reset functionality. Users communicate with the server via HTTP POST requests, where parameters like 'action', 'sb_data', and 'sb_new_password' manage password resets. However, due to insufficient validation checks especially for the 'token' parameter, attackers can manipulate these requests to reset passwords without needed authorization. Specifically, the endpoints 'admin-ajax.php' and 'wp-login.php' are susceptible when sending crafted requests. Upon successful exploitation, an unauthorized login becomes feasible.

Exploitation of this vulnerability can lead to severe impacts, particularly unauthorized access to sensitive accounts. An attacker could take control of administrative accounts, leading to complete site compromise. They may alter, delete, or leak sensitive information, post fake job listings, or demand ransom for regaining access control. This breach can result in reputational damage, loss of user trust, and potentially legal repercussions for failing to protect user data. Preventive measures should be implemented immediately to mitigate these risks.

REFERENCES

Solution Advice
  • Update the Nokri – Job Board WordPress Theme to a secure version immediately.
  • Implement stringent validation checks for all input fields, especially for token parameters.
  • Regularly audit and monitor user account activities for any unauthorized changes.
  • Deploy multi-factor authentication to enhance account security.
  • Educate administrators on recognizing and responding to suspicious activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.