ZeroHour

CVE-2025-4094

PoC
CVSS 3.1
9.8 critical
EPSS
16%p97
Published
()
Modified
Description

The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.

Vendors
unitedover
Products
digits
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.