CVE 9.8 CRITICAL

Password Reset with Code < 0.0.17 - Insecure Password Reset Code Creation_CVE-2025-5305

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.

Basic Information

ID CVE-2025-5305
Source WPScan
Published Sep 18, 2025 at 06:00
Modified Sep 22, 2025 at 17:27

Affected Product

Vendor Unknown
Product Password Reset with Code for WordPress REST API
Affected Versions Unknown Password Reset with Code for WordPress REST API 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.