CVE-2026-66691 CRITICAL

CVE-2026-66691: WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability

Vendor Scriptsbundle
Product Nokri
Weakness CWE-640 · Weak password recovery
Published August 13, 2026
Last update August 13, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.

Explanation of Vulnerability in Simple Terms

02Summary

Nokri versions up to 1.6.6 use a weak password recovery mechanism that allows attackers to reset user passwords without proper verification. An attacker can exploit this flaw over the network without authentication to gain unauthorized access to user accounts. The vulnerability affects confidentiality, integrity, and availability of the application.

What an attacker can do

03Attacker Capabilities

Reset any user's password and take over their account without authentication.

Potential impact on your site

04Site Impact

Attackers can compromise any user account, including administrators, leading to full site takeover.

Conditions required to exploit

05Prerequisites

Network access to the Nokri application; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 13, 2026 CVE published

Related vulnerabilities

08Related CVE