CVE-2025-4094

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/05/2025
Last modified:
09/06/2025

Description

The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:unitedover:digits:*:*:*:*:*:wordpress:*:* 8.4.6.1 (excluding)