Junglewise Threat Intelligence

CVE-2026-28165: Digits WordPress Plugin unauthenticated privilege escalation

CVE-2026-28165 · Severity: critical · CVSS 9.8 · Published 2026-08-24

Executive brief

The Digits WordPress plugin is a form builder and contact management tool used by thousands of websites. A critical flaw allows unauthenticated attackers to escalate their privileges to administrator level and gain complete control of an affected WordPress site, including the ability to modify content, steal data, or install malicious code. No official patch is currently available.

Technical details

The vulnerability is a privilege escalation (OWASP A7: Identification and Authentication Failures) affecting Digits plugin versions 9.2 and earlier. An unauthenticated attacker can exploit this flaw to escalate to administrator-level access without requiring authentication. The exact attack vector and vulnerable component are not fully detailed, but the high CVSS score (9.8) and lack of authentication requirements suggest a direct and easily exploitable flaw. As of the advisory date, no official patch has been released; Patchstack has provided a WAF-level mitigation rule to block attack patterns.

Affected products

  • Digits Digits 9.2 and earlier

Timeline

  • 2026-08-24: disclosed: CVE-2026-28165 published on NVD
  • 2026-07-21: reported: Reported to Patchstack by VanTastic

References