Digits: WordPress Mobile Number Signup and Login <= 9.2 - Unauthenticated Privilege Escalation
high
The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.2. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for unauthenticated attackers to elevate their privil...
- CVSS:
- 7.3
- Affected:
- up to 9.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 20, 2026
CVE-2026-28165 on NVD →
Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' Parameter
high
The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This is due to missing authorization and role validation in the `dig_update_wpwc_custom_fields()` function. This makes it possible for authenticated attackers, w...
- CVSS:
- 8.8
- Affected:
- up to 9.1.0.5
- Fixed in:
- 9.1.0.6
- Disclosed:
- Jul 15, 2026
CVE-2026-13741 on NVD →
Digits < 8.4.6.1 - Authentication Bypass via Weak OTP
critical
The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to 8.4.6.1 (exclusive). This is due to the plugin not using a sufficiently strong OTP or implementing OTP brute force protection. This makes it possible for unauthenticated attackers to ga...
- CVSS:
- 9.8
- Affected:
- up to 8.4.6.1
- Fixed in:
- 8.4.6.1
- Disclosed:
- Apr 30, 2025
CVE-2025-4094 on NVD →
Digits <= 8.4.1 - Cross-Site Request Forgery to Privilege Escalation
high
The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation in the 'digits_save_settings' function. This makes it possible for unauthenticated attackers to modify the default role of registered users to elevate user privile...
- CVSS:
- 8.8
- Affected:
- 8.4.1 – 8.4.1
- Fixed in:
- 8.4.2
- Disclosed:
- Feb 22, 2024
CVE-2024-0203 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database