The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Sep 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wordpress
Wordpress wordpress |
|
Vendors & Products |
Wordpress
Wordpress wordpress |
Thu, 18 Sep 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers. | |
Title | Password Reset with Code < 0.0.17 - Insecure Password Reset Code Creation | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-09-18T06:00:04.273Z
Updated: 2025-09-18T06:00:04.273Z
Reserved: 2025-05-28T13:47:13.132Z
Link: CVE-2025-5305

No data.

Status : Awaiting Analysis
Published: 2025-09-18T06:15:34.887
Modified: 2025-09-18T13:43:34.310
Link: CVE-2025-5305

No data.