medium · CVSS v3 4.4 · EPSS 0.00195
CVE-2026-12402
The OTP Login & Register WooCommerce plugin for WordPress is vulnerable to stored XSS via the 'fb-config' setting. Authenticated administrat
Overview
The OTP Login & Register WooCommerce plugin for WordPress is vulnerable to stored XSS via the 'fb-config' setting. Authenticated administrators can inject scripts that execute for any user who views the affected page, enabling session hijacking or site defacement.
Description
The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' Setting in all versions up to, and including, 2.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. On multisite installations where administrators do not hold the unfiltered_html capability, this vulnerability can be leveraged to target the network super administrator.
Impact
Confidentiality: attackers can exfiltrate data through injected scripts. Integrity: malicious code can alter page content or redirect users. Availability: not directly impacted. Affected parties: site administrators with admin rights and all visitors who load the compromised page.
Remediation
Update the plugin to version 2.7.4 or later where input sanitization and output escaping are fixed. If an update is not possible, disable or restrict the 'fb-config' setting to trusted users only. Ensure the 'unfiltered_html' capability is granted only to super administrators and monitor for unexpected script injections.
Risk context
The CVE has medium severity (CVSS 4.4) but a very low EPSS score of 0.00195, indicating a low likelihood of exploitation. Nonetheless, because the flaw requires administrator access, defenders should patch promptly to mitigate potential internal misuse.
Affected products
- WordPress OTP Login & Register WooCommerce plugin
Scores
- Severity
- medium
- CVSS v2
- 3.2
- CVSS v3
- 4.4
- CVSS v4
- —
- EPSS
- 0.00195