CVE-2026-28165 describes an unauthenticated privilege escalation vulnerability affecting the Digits WordPress plugin in versions 9.2 and below. The flaw allows unauthenticated users to escalate their privileges, potentially gaining administrative or elevated access without any prior authentication. This type of vulnerability poses a critical risk to WordPress sites using the affected plugin. The vulnerability is documented on the NVD and has been reported via Patchstack. Users are advised to update the Digits plugin beyond version 9.2 to remediate the issue. No exploitation details or active in-the-wild exploitation have been explicitly mentioned, but the unauthenticated nature makes it high severity.