CVE-2026-28165: WordPress Digits plugin <= 9.2 - Privilege Escalation vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
Affected Software
1 affected component
WordPress Digits plugin<=9.2
Event History
Aug 24, 2026
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or prior privileges to attempt exploitation.
2
Which installations are affected?
Digits plugin versions 9.2 and earlier are identified as affected. The provided information does not state whether any particular plugin configuration is required.
3
What is the potential impact?
Successful exploitation can result in privilege escalation. The assigned critical severity vector indicates network-reachable exploitation with low attack complexity and high impacts to confidentiality, integrity, and availability.