A critical unauthenticated privilege escalation vulnerability has been identified in the Digits WordPress plugin affecting versions up to and including 9.2. The vulnerability allows unauthenticated attackers to escalate their privileges, potentially gaining administrative access to affected WordPress installations. The flaw is tracked as CVE-2026-28165 and has been documented by both the NVD and Patchstack. No authentication is required to exploit this vulnerability, making it particularly dangerous. WordPress site administrators using the Digits plugin should update to a patched version immediately. The vulnerability was reported via Patchstack's WordPress vulnerability database. The high severity rating reflects the risk of complete site compromise without any prior authentication.