Digits
- <= 9.1.0.5
A privilege escalation vulnerability has been identified in the Digits: WordPress Mobile Number Signup and Login plugin, affecting all versions through 9.1.0.5. The issue arises from inadequate authorization and role validation in the 'dig_update_wpwc_custom_fields()' function. This vulnerability allows authenticated attackers with Subscriber-level access or higher to escalate their privileges to Administrator by submitting a fake 'digits_reg_userrole' value during profile updates, provided the site administrator has enabled the DIGITS User Role field.
Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling a user with Subscriber-level access to gain Administrator rights.
Users can update to version 9.1.0.6 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.