Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29845 | The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers. |
Mon, 22 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 18 Sep 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Thu, 18 Sep 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers. | |
| Title | Password Reset with Code < 0.0.17 - Insecure Password Reset Code Creation | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-09-22T17:27:38.830Z
Reserved: 2025-05-28T13:47:13.132Z
Link: CVE-2025-5305
Updated: 2025-09-22T16:58:40.307Z
Status : Deferred
Published: 2025-09-18T06:15:34.887
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-5305
No data.
OpenCVE Enrichment
Updated: 2025-09-18T12:41:00Z
No weakness.
EUVD