← WordPress Vulnerabilities
WordPress security by component

DIGITS: WordPress Mobile Number Signup and Login

DIGITS: WordPress Mobile Number Signup and Login adds mobile-number-based signup and login functionality to WordPress websites.

DIGITS: WordPress Mobile Number Signup and Login (digits) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 24, 2026; the highest published CVSS base score is 9.8.

Plugin slug: digits

CVE-2026-28165: Digits permits unauthenticated privilege escalation

Digits through 9.2 permits an unauthenticated attacker to cross a privilege boundary and obtain elevated access. The CNA rates confidentiality, integrity, and availability impact as high.

PublishedAug 24, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for digits
Safe version
Aug 24, 2026 CVE-2026-28165
Digits permits unauthenticated privilege escalation
Digits through 9.2 permits an unauthenticated attacker to cross a privilege boundary and obtain elevated access. The CNA rates confidentiality, integrity, and availability impact as high.
See mitigation notes
CVE9.8
NVDPending
May 21, 2025 CVE-2025-4094
DIGITS: WordPress Mobile Number Signup and Login: A security weakness
DIGITS: WordPress Mobile Number Signup and Login is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVDPending
Mar 07, 2024 CVE-2024-0203
Digits: Cross-site request forgery
Digits is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVDPending