Executive brief
The OTP Login & Register Woocommerce plugin for WordPress allows administrators to inject malicious scripts that persist and execute for all users visiting affected pages. An attacker with admin-level access can compromise site functionality, steal user data, or hijack administrator accounts by exploiting insufficient input validation on the 'fb-config' setting. On WordPress multisite networks, this can escalate to compromise the network super administrator.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the 'fb-config' setting due to inadequate input sanitization and output escaping. Authenticated users with administrator privileges can inject arbitrary JavaScript that persists in the database and executes in the browsers of all site visitors. The vulnerability affects all versions up to and including 2.7.3; on multisite installations lacking the unfiltered_html capability, even regular administrators can exploit this to target the super administrator.
Affected products
- OTP Login & Register Woocommerce up to and including 2.7.3
Timeline
- 2026-09-19: disclosed