
WordPress Digits Plugin 8.4.6.1 – Authentication Bypass via OTP Bruteforcing
# Exploit Title: WordPress Digits Plugin 8.4.6.1 – Authentication Bypass via OTP Bruteforcing # Google Dork: inurl:/wp-content/plugins/digits/ # Date: 2025-04-30 # Exploit Author: Saleh Tarawneh # Vendor Homepage: https://digits.unitedover.com/ # Version: < 8.4.6.1 # CVE : CVE-2025-4094 “”” The Digits plugin for WordPress prior to version 8.4.6.1 is vulnerable to OTP brute-force attacks…