Record summary

CVE-2025-4094 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 2 repository PoCs.

Description

The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
2

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 21, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

DIGITS: WordPress Mobile Number Signup and Login

Default status: unaffected

CVE ListBefore 8.4.6.1affected

Proofs of concept

3

Catalogued exploits

ExploitDBWordPress Digits Plugin 8.4.6.1 - Authentication Bypass via OTP BruteforcingExploitDB exploitby Saleh TarawnehNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubstarawneh/CVE-2025-4094Repository PoCby starawnehStars: 1Not analyzed2 files

4.9 KiB

GitHub

PoC details
GitHubPOCPioneer/CVE-2025-4094-POCRepository PoCby POCPioneerStars: 2Not analyzed3 files

7.1 KiB

GitHub

PoC details

References

2