CVE-2025-4094: Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
Published May 21, 2025
·Updated
The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.
Affected Software
2 affected components
WordPress DIGITS<8.4.6.1
Unitedover Digits Wordpress<8.4.6.1
Event History
May 21, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
May 29, 2025
Exploit Published
12:00 AM
Known Exploited
10:17 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-4094?
CVE-2025-4094 is considered a high severity vulnerability due to the lack of rate limiting on OTP validations.
2
How do I fix CVE-2025-4094?
To fix CVE-2025-4094, update the WordPress DIGITS plugin to version 8.4.6.1 or later.
3
What type of attack does CVE-2025-4094 enable?
CVE-2025-4094 enables attackers to easily brute force OTP validation attempts.
4
What versions of WordPress DIGITS are affected by CVE-2025-4094?
CVE-2025-4094 affects WordPress DIGITS versions before 8.4.6.1.
5
Is CVE-2025-4094 easily exploitable?
Yes, CVE-2025-4094 is easily exploitable due to the lack of rate limiting on OTP validation.