Digits < 8.4.6.1 - Authentication Bypass via Weak OTP
Strategic Overview
< 8.4.6.1CVE-2025-4094Vulnerability Overview
The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to 8.4.6.1 (exclusive). This is due to the plugin not using a sufficiently strong OTP or implementing OTP brute force protection. This makes it possible for unauthenticated attackers to gain access to other user's accounts, including administrators, if the OTP is successfully brute forced.
Technical Analysis
REMEDIATION: Update to version 8.4.6.1, or a newer patched version --- IDENTIFIER: CWE-1390 (Weak Authentication) The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C