What the vulnerability does
01Description
Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress REST API: from n/a through 0.0.15.
Explanation of Vulnerability in Simple Terms
02Summary
The Password Reset with Code plugin for WordPress REST API versions up to 0.0.15 contains a flaw that allows unauthenticated attackers to run arbitrary code on the site. The vulnerability stems from improper rate limiting or validation of password reset tokens, enabling attackers to bypass authentication and execute PHP code with full site privileges.
What an attacker can do
03Attacker Capabilities
Run arbitrary PHP code on the site and take complete control without needing a valid account.
Potential impact on your site
04Site Impact
Complete site compromise: attackers can steal data, modify content, install backdoors, or take the site offline.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
December 7, 2023
CVE published
April 28, 2026
Record updated