Digits WordPress Plugin Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in the Digits: WordPress Mobile Number Signup and Login plugin, affecting all versions through 9.1.0.5. The issue arises from inadequate authorization and role validation in the 'dig_update_wpwc_custom_fields()' function. This vulnerability allows authenticated attackers with Subscriber-level access or higher to escalate their privileges to Administrator by submitting a fake 'digits_reg_userrole' value during profile updates, provided the site administrator has enabled the DIGITS User Role field.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling a user with Subscriber-level access to gain Administrator rights.

Remediation

Users can update to version 9.1.0.6 or a newer patched version to address this vulnerability.

Added: Jul 16, 2026, 9:55 AM
Updated: Jul 16, 2026, 9:55 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.