Unitedover

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 4
    Known Exploited: 0
    2
    Critical Level Threats
    2
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-28165

    WordPress Digits plugin <= 9.2 - Privilege Escalation vulnerability

    Last Modified: Aug 24, 2026
    Published: Aug 24, 2026

    CVE-2026-13741

    Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' Parameter

    Last Modified: Jul 23, 2026
    Published: Jul 16, 2026

    CVE-2025-4094

    Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing

    Last Modified: Aug 27, 2025
    Published: May 21, 2025

    CVE-2024-0203

    The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation in the 'digits_save_settings' function. This makes it possible for unauthenticated attackers to modify the default role of registered users to elevate user privileges via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Last Modified: Jan 21, 2025
    Published: Mar 07, 2024
    Items Per Page
    Unitedover Vulnerabilities & Security CVEs | CVE-DB