cleantalk
Vulnerabilities and Security Researches

Password Reset with Code for WordPress REST API, CVE-2025-5305

CVE, Research URL

CVE-2025-5305

Published on
Sep 18, 2025
Research Description
The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.
Affected versions
max 0.0.17.
Status
vulnerable