
CVE-2025-4094-POC
WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)
authentication-authorizationexploitationpassword-attacks+3
2

WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

Brute Force Wordpress Blogs.