Impact
The Digits: WordPress Mobile Number Signup and Login plugin allows an authenticated attacker who has at least Subscriber privileges to raise their role to Administrator. The flaw exists because the plugin’s update function lacks proper authorization checks and role validation. By submitting a forged "digits_reg_userrole" parameter while updating their profile, a logged‑in user can alter the role field and gain admin rights.
Affected Systems
The vulnerability affects the UnitedOver Digits: WordPress Mobile Number Signup and Login plugin for WordPress versions up to and including 9.1.0.5. All sites that have installed these affected plugin versions and have the built‑in DIGITS User Role field enabled are susceptible.
Risk and Exploitability
With a CVSS score of 8.8, the issue presents a high severity risk. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires the attacker to be an authenticated subscriber or higher; exploitation would involve sending a crafted request containing the "digits_reg_userrole" value during the profile update process. No public exploit is known, but the lack of authorization controls makes the flaw straightforward to trigger for logged‑in users.
OpenCVE Enrichment