plugin

Digits Vulnerabilities

4 known security issues reported for the Digits WordPress plugin. Most recent disclosed Aug 20, 2026.

1 critical 3 high

Running Digits on your site? Check whether your installed version is affected.

Scan your site free

Digits: WordPress Mobile Number Signup and Login <= 9.2 - Unauthenticated Privilege Escalation

high

The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.2. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for unauthenticated attackers to elevate their privil...

CVSS:
7.3
Affected:
up to 9.2
Fix:
No patched version reported
Disclosed:
Aug 20, 2026

CVE-2026-28165 on NVD →

Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' Parameter

high

The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This is due to missing authorization and role validation in the `dig_update_wpwc_custom_fields()` function. This makes it possible for authenticated attackers, w...

CVSS:
8.8
Affected:
up to 9.1.0.5
Fixed in:
9.1.0.6
Disclosed:
Jul 15, 2026

CVE-2026-13741 on NVD →

Digits < 8.4.6.1 - Authentication Bypass via Weak OTP

critical

The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to 8.4.6.1 (exclusive). This is due to the plugin not using a sufficiently strong OTP or implementing OTP brute force protection. This makes it possible for unauthenticated attackers to ga...

CVSS:
9.8
Affected:
up to 8.4.6.1
Fixed in:
8.4.6.1
Disclosed:
Apr 30, 2025

CVE-2025-4094 on NVD →

Digits <= 8.4.1 - Cross-Site Request Forgery to Privilege Escalation

high

The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation in the 'digits_save_settings' function. This makes it possible for unauthenticated attackers to modify the default role of registered users to elevate user privile...

CVSS:
8.8
Affected:
8.4.1 – 8.4.1
Fixed in:
8.4.2
Disclosed:
Feb 22, 2024

CVE-2024-0203 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database