External risk intelligence

Nokri Theme Broken Access Control Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-66691

Nokri is a WordPress theme. WordPress themes are commonly deployed as part of public-facing web applications, making the underlying code reachable via the internet by design to serve web traffic.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Nokri WordPress theme that allows unauthorized access to system functions due to flaws in access control. This could potentially expose sensitive information or allow for system manipulation. The main concern is to confirm if this theme is in use within our environment and assess any potential exposure.

  • Unauthenticated access flaw in a WordPress theme.
  • Matters because it could allow unauthorized system access.
  • Confirm relevance and check for potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by accessing a Nokri theme installation over the internet without needing any authentication. By targeting a specific access control weakness, they could then potentially gain administrative privileges or access sensitive data. This could lead to the compromise of the entire website.

  • No authentication required to start.
  • Exploits broken access control.
  • Leads to full website compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to access sensitive information or perform unauthorized actions within the Nokri theme when supported by the advisory. This could impact the integrity and confidentiality of data handled by the theme.

  • Theme data and settings at risk.
  • Unauthenticated network access.
  • Unauthorized system modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

This unauthenticated broken access control vulnerability in Nokri affects public-facing web applications using the Nokri theme, making it reachable via the internet. The first practical step is to identify all deployments of the affected theme, confirm its reachability and business criticality, and then engage the responsible team—likely the application owner or platform team managing the WordPress instance—to plan remediation based on assessed risk.

  • Application owners should prioritize this issue.
  • Verify affected Nokri theme deployments.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Nokri theme?

Nokri is a WordPress theme designed to facilitate job board functionality on websites. It acts as a structural and design framework that controls how job listings, resumes, and user accounts appear and interact within a WordPress site.

What does CVE-2026-66691 mean for security?

This CVE represents a Broken Access Control vulnerability, classified as CWE-640. It means the software fails to properly restrict who can access or modify specific system functions, allowing users to bypass security checks that should normally prevent unauthorized actions.

How does an attacker trigger this vulnerability?

An attacker triggers this flaw by interacting with the Nokri theme over a network without needing a username or password. Simply being an authenticated user of the site is not a requirement; the bug exists because the software incorrectly processes requests from unauthenticated sources.

Do I need to worry if my Nokri site is internal?

Halo Surface Signal indicates that because Nokri is a WordPress theme, it is typically deployed on public-facing web applications to serve content to internet users. While external sites are at higher risk, you should verify if your instance is reachable from the internet, as that significantly increases the potential for unauthorized access.

When should I take action for this vulnerability?

Start by identifying every WordPress instance in your environment using the Nokri theme. Once you confirm where it is deployed, coordinate with the specific application owners or platform teams to assess the risk and prepare for updates or configuration changes.

References