Description
The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.
Problem types
CWE-326 Inadequate Encryption Strength
Product status
Any version before 0.0.17
Credits
Tommaso Gregori (p1s1o)
WPScan
References
wpscan.com/...rability/dcf5c003-91b0-4e7d-89f3-7459d8f01153/
wpscan.com/...rability/dcf5c003-91b0-4e7d-89f3-7459d8f01153/