CVE-2025-4094
Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · DIGITS: WordPress Mobile Number Signup and Loginpublic PoCs found — 4
githubgithub.com/POCPioneer/CVE-2025-4094-POC★ 2githubgithub.com/starawneh/CVE-2025-4094★ 1exploitdbwww.exploit-db.com/exploits/52307unverifiedcve_referencewpscan.com/vulnerability/b5f0a263-644b-4954-a1f0-d08e2149edbb/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →