Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-4094 — CVE-2025-4094 – WordPress Digits Plugin < 8.4.6.1 - OTP Authentication Bypass | Kitploit
Tools/GitHubGitHub/starawneh/cve-2025-4094
Password AttacksVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingAuthentication
GitHubstarawneh/cve-2025-4094

CVE-2025-4094

CVE-2025-4094 – WordPress Digits Plugin < 8.4.6.1 - OTP Authentication Bypass

View Repository
181 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-4094 – WordPress Digits Plugin < 8.4.6.1 - OTP Authentication Bypass

Author: Saleh Tarawneh
CVE ID: CVE-2025-4094
Severity: Critical (CVSS 9.8)
Status: Fixed in version 8.4.6.1


Vulnerability Description

The Digits WordPress plugin prior to version 8.4.6.1 is vulnerable to OTP brute-force attacks due to missing rate limiting. This allows unauthenticated attackers to bypass SMS OTP-based authentication and reset passwords.

  • CWE-287: Improper Authentication
  • OWASP A2: Broken Authentication

Proof of Concept

Option 1: Python Script (Automated)

Edit the placeholders inside digits_otp_bypass_cve2025-4094.py:

  • digits_phone
  • instance_id
  • digits_form
  • Referer / redirect_page
  • Any other required values from the intercepted request

Then run:

python3 digits_otp_bypass_cve2025-4094.py

Option 2: Burp Suite Pro (Manual Brute Force)

You can also perform the attack using Burp Suite Pro and Intruder:

  1. Intercept the OTP verification request using Burp Proxy during login or "Forgot Password" flow.
  2. Right-click the request → Send to Intruder
  3. Set the payload position on the sms_otp parameter.
  4. Load a payload list from 000000 to 999999:
  5. Start the attack and monitor for a successful response by checking:
    • "success":true in the body
    • Change in response length

This method is useful for visual inspection and fine-tuning detection thresholds within Burp.

Enhanced Script

  • Enhanced PoC By POCPioneer

References

  • WPScan Vulnerability Entry
  • WPVulnDB Entry
  • Official Plugin Page
  • CVE ID – CVE-2025-4094
Download Tool