The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Sep 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 18 Sep 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wordpress
Wordpress wordpress |
|
Vendors & Products |
Wordpress
Wordpress wordpress |
Thu, 18 Sep 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers. | |
Title | Password Reset with Code < 0.0.17 - Insecure Password Reset Code Creation | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-09-22T17:27:38.830Z
Reserved: 2025-05-28T13:47:13.132Z
Link: CVE-2025-5305

Updated: 2025-09-22T16:58:40.307Z

Status : Awaiting Analysis
Published: 2025-09-18T06:15:34.887
Modified: 2025-09-22T18:15:47.090
Link: CVE-2025-5305

No data.