Beveiligingsadvies

CVE-2025-5305

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-09-18 06:00:04
Laatst bijgewerkt 2025-09-22 17:27:38
Toegewezen door WPScan
CVSS-score 9.8
Status PUBLISHED

Beschrijving

The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.