nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-4094 CVE-2025-4094
CRITICAL
Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
Record summary
CVE-2025-4094 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 2 repository PoCs.
Description
The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DIGITS: WordPress Mobile Number Signup and LoginDefault status: unaffected | CVE List | Before 8.4.6.1 | affected |
Proofs of concept
3Catalogued exploits
ExploitDBWordPress Digits Plugin 8.4.6.1 - Authentication Bypass via OTP BruteforcingExploitDB exploitby Saleh TarawnehNot analyzed1 file
Repository PoCs
GitHubstarawneh/CVE-2025-4094Repository PoCby starawnehStars: 1Not analyzed2 files
GitHubPOCPioneer/CVE-2025-4094-POCRepository PoCby POCPioneerStars: 2Not analyzed3 files
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/b5f0a263-644b-4954-a1f0-d08e2149edbb