Impact
The OTP Login & Register Woocommerce plugin allows storage of user‑supplied data in the 'fb‑config' setting without proper sanitization or escaping. An authenticated user with administrator or higher privileges can enter malicious JavaScript into this field, which is then rendered in pages that display the configuration value. Any visitor to such a page will have the injected script executed in their browser, creating a risk of session hijacking, credential theft, or other client‑side attacks.
Affected Systems
All WordPress sites that have an installation of the xootix OTP Login & Register Woocommerce plugin at version 2.7.3 or earlier are affected. The flaw exists in both single‑site and multisite WordPress deployments; administrators who can modify the 'fb‑config' setting may embed the script under the entire network when using the super‑administrator account.
Risk and Exploitability
With a CVSS score of 4.4 the vulnerability is rated moderate. The EPSS indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because only privileged administrators can inject the payload, the attack vector requires authenticated access through the plugin’s admin interface. Sites that tightly control admin accounts or use strong credential policies will have a lower risk, but a successful injection remains dangerous for all site visitors.
OpenCVE Enrichment