PT-2025-38299 · WordPress · Password Reset With Code For Wordpress Rest Api

·

CVE-2025-5305

·

Published

2025-09-18

·

Updated

2025-11-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Password Reset with Code for WordPress REST API plugin versions prior to 0.0.17
Description The plugin does not employ cryptographically secure algorithms for generating One-Time Password (OTP) codes, which could allow for account takeovers.
Recommendations Update the Password Reset with Code for WordPress REST API plugin to version 0.0.17 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2025-5305

Affected Products

Password Reset With Code For Wordpress Rest Api