Password Reset with Code < 0.0.17 - Insecure Password Reset Code Creation
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · Password Reset with Code for WordPress REST API