Password Reset with Code <= 0.0.16 - Unauthenticated Privilege Escalation via Weak OTP Codes

2025-08-28 00:00
Tommaso Gregori

Strategic Overview

Status
Patched in 0.0.17
Affected Version<= 0.0.16
CVSS8.1High
CVECVE-2025-5305
View all Password Reset with Code for WordPress REST API vulnerabilities

Vulnerability Overview

The Password Reset with Code for WordPress REST API plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.0.16. This is due to the plugin not using cryptographically secure mechanisms for OTP generation This makes it possible for unauthenticated attackers to reset users, including administrators, passwords and leverage that to gain access to their accounts.

Technical Analysis

REMEDIATION: Update to version 0.0.17, or a newer patched version --- IDENTIFIER: CWE-326 (Inadequate Encryption Strength) The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C