Junglewise Threat Intelligence

CVE-2026-13741: UnitedOver Digits WordPress Plugin privilege escalation

CVE-2026-13741 · Severity: high · CVSS 8.8 · Published 2026-07-16

Executive brief

The Digits plugin for WordPress, which allows users to sign up and log in using mobile numbers, contains a security flaw that allows standard users to upgrade their own accounts to Administrator status. By exploiting this vulnerability, an attacker with a basic account can gain full control over the website, potentially leading to data theft, site defacement, or complete service disruption. This issue affects sites where the administrator has enabled the built-in Digits User Role field.

Technical details

The Digits plugin for WordPress is vulnerable to privilege escalation in versions up to and including 9.1.0.5 due to missing authorization and role validation in the `dig_update_wpwc_custom_fields()` function. An authenticated attacker with Subscriber-level permissions can exploit this by submitting a forged `digits_reg_userrole` value during a profile update. This attack is successful if the site administrator has configured the built-in DIGITS User Role field. Successful exploitation allows the attacker to escalate their privileges to Administrator. The issue is addressed in version 9.2.

Affected products

  • UnitedOver Digits: WordPress Mobile Number Signup and Login 0 - 9.1.0.5

Timeline

  • 2026-07-07: patched: Version 9.2 released
  • 2026-07-16: disclosed: CVE published

References