CVE-2025-4094

Publication date

2025-05-21 06:00:09

Family

WPScan

State

PUBLISHED

Description

The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.