HomeDefault status
unaffected
Any version before 8.4.6.1
affected
Description
The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.
Problem types
CWE-307 Improper Restriction of Excessive Authentication Attempts
Product status
Any version before 8.4.6.1
Credits
Saleh Tarawneh
WPScan
References
wpscan.com/...rability/b5f0a263-644b-4954-a1f0-d08e2149edbb/