The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 18 Sep 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers. | |
Title | Password Reset with Code < 0.0.17 - Insecure Password Reset Code Creation | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-09-18T06:00:04.273Z
Reserved: 2025-05-28T13:47:13.132Z
Link: CVE-2025-5305

No data.

Status : Received
Published: 2025-09-18T06:15:34.887
Modified: 2025-09-18T06:15:34.887
Link: CVE-2025-5305

No data.

No data.