Home

Description

The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.

PUBLISHED Reserved 2025-05-28 | Published 2025-09-18 | Updated 2025-09-22 | Assigner WPScan

Problem types

CWE-326 Inadequate Encryption Strength

Product status

Default status
unaffected

Any version before 0.0.17
affected

Credits

Tommaso Gregori (p1s1o) finder

WPScan coordinator

References

wpscan.com/...rability/dcf5c003-91b0-4e7d-89f3-7459d8f01153/ exploit

wpscan.com/...rability/dcf5c003-91b0-4e7d-89f3-7459d8f01153/ exploit vdb-entry technical-description

cve.org (CVE-2025-5305)

nvd.nist.gov (CVE-2025-5305)

Download JSON