Executive brief
The Digits WordPress plugin is a form builder and contact management tool used by thousands of websites. A critical flaw allows unauthenticated attackers to escalate their privileges to administrator level and gain complete control of an affected WordPress site, including the ability to modify content, steal data, or install malicious code. No official patch is currently available.
Technical details
The vulnerability is a privilege escalation (OWASP A7: Identification and Authentication Failures) affecting Digits plugin versions 9.2 and earlier. An unauthenticated attacker can exploit this flaw to escalate to administrator-level access without requiring authentication. The exact attack vector and vulnerable component are not fully detailed, but the high CVSS score (9.8) and lack of authentication requirements suggest a direct and easily exploitable flaw. As of the advisory date, no official patch has been released; Patchstack has provided a WAF-level mitigation rule to block attack patterns.
Affected products
- Digits Digits 9.2 and earlier
Timeline
- 2026-08-24: disclosed: CVE-2026-28165 published on NVD
- 2026-07-21: reported: Reported to Patchstack by VanTastic