Password Reset with Code <= 0.0.16 - Unauthenticated Privilege Escalation via Weak OTP Codes
high
The Password Reset with Code for WordPress REST API plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.0.16. This is due to the plugin not using cryptographically secure mechanisms for OTP generation This makes it possible for unauthenticated attackers to reset users, inc...
- CVSS:
- 8.1
- Affected:
- up to 0.0.16
- Fixed in:
- 0.0.17
- Disclosed:
- Aug 28, 2025
CVE-2025-5305 on NVD →
Password Reset with Code for WordPress REST API [bdvs-password-reset] < 0.0.16
unknown
[en] Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress REST API: from n/a through 0.0.15.
- Affected:
- up to 0.0.16
- Fixed in:
- 0.0.16
- Disclosed:
- Dec 7, 2023
CVE-2023-35039 on NVD →
Password Reset with Code for WordPress REST API <= 0.0.15 - Weak Password Recovery Mechanism
critical
The Password Reset with Code for WordPress REST API is vulnerable to a Weak Password Recovery Mechanism in versions up to, and including, 0.0.15. This allows unauthenticated attackers to set a 4-digit password recovery code for arbitrary users that, if guessed correctly, will allow them to reset the password for that u...
- CVSS:
- 9.8
- Affected:
- up to 0.0.15
- Fixed in:
- 0.0.16
- Disclosed:
- Aug 14, 2023
CVE-2023-35039 on NVD →
Password Reset with Code for WordPress REST API [bdvs-password-reset] < 0.0.17
unknown
- Affected:
- up to 0.0.17
- Fixed in:
- 0.0.17
CVE-2025-5305 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database