
CVE-2025-4094 – WordPress Digits Plugin < 8.4.6.1 - OTP Authentication Bypass
Author: Saleh Tarawneh
CVE ID: CVE-2025-4094
Severity: Critical (CVSS 9.8)
Status: Fixed in version 8.4.6.1
The Digits WordPress plugin prior to version 8.4.6.1 is vulnerable to OTP brute-force attacks due to missing rate limiting. This allows unauthenticated attackers to bypass SMS OTP-based authentication and reset passwords.
Edit the placeholders inside digits_otp_bypass_cve2025-4094.py:
digits_phoneinstance_iddigits_formReferer / redirect_pageThen run:
python3 digits_otp_bypass_cve2025-4094.py
You can also perform the attack using Burp Suite Pro and Intruder:
sms_otp parameter.000000 to 999999:"success":true in the bodyThis method is useful for visual inspection and fine-tuning detection thresholds within Burp.