The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Digits | Unitedover | * | 8.4.6.1 (excluding) |
References