CVE-2025-4094: Unitedover Digits
Critical severity, CVSS 9.8. EPSS: 15.8% chance of exploitation in the next 30 days.
The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.
Affected products
- Unitedover Digits: before 8.4.6.1 (fixed in 8.4.6.1)
Published 2025-05-21. Last modified 2026-06-17.