PT-2025-38299 · WordPress · Password Reset With Code For Wordpress Rest Api

Tommaso Gregori

·

Published

2025-09-18

·

Updated

2025-11-26

·

CVE-2025-5305

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Password Reset with Code for WordPress REST API plugin versions prior to 0.0.17
Description The plugin does not employ cryptographically secure algorithms for generating One-Time Password (OTP) codes, which could allow for account takeovers.
Recommendations Update the Password Reset with Code for WordPress REST API plugin to version 0.0.17 or later.

Exploit

Fix

Related Identifiers

CVE-2025-5305

Affected Products

Password Reset With Code For Wordpress Rest Api