Stored Cross-Site Scripting Vulnerability in OTP Login & Register Woocommerce Plugin for WordPress
CVE-2026-12402
4.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 September 2026
What is CVE-2026-12402?
The OTP Login & Register Woocommerce plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in the 'fb-config' settings. This vulnerability can allow authenticated attackers, with administrator-level access, to inject malicious scripts into pages, which can then execute whenever users visit those pages. On multisite environments lacking the unfiltered_html capability, this flaw poses a significant risk to network super administrators, facilitating potential exploitation across the WordPress network.
Affected Version(s)
OTP Login & Register Woocommerce 0 <= 2.7.3