Yes, I think that's what basically the code is, some kind of a one time password. The fact it is just 5 digits is not something I've paid a lot of attention to be honest, as this is something really easy to change. Probably you could even use letters, symbols, etc... the trade-off is annoying a bit more the end user.
It also expires (see https://github.com/msurdi/wipku/blob/master/server/core/user...) , and the api should probably protected with rate limits, that should mitigate the brute force attacks I think.