PoC Index

CVE-2025-5305

CRITICAL 9.8EPSS 0.2%

The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.24% chance of exploitation in the next 30 days, 14th percentile
Published
2025-09-18
Updated
2025-09-22

Proof-of-concept exploits (1)

References

Related