CVE-2026-12402 Overview
CVE-2026-12402 is a Stored Cross-Site Scripting (XSS) vulnerability in the OTP Login & Register WooCommerce plugin for WordPress. The flaw affects all versions up to and including 2.7.3. The vulnerability resides in the fb-config setting, where insufficient input sanitization and output escaping allow authenticated attackers with administrator-level access to inject arbitrary web scripts. Injected scripts execute when any user accesses an affected page. On multisite installations where administrators lack the unfiltered_html capability, attackers can leverage the flaw to target the network super administrator. The vulnerability is tracked under [CWE-79].
Critical Impact
Authenticated administrators can inject persistent JavaScript that executes in the browsers of other users, including multisite super administrators who otherwise restrict unfiltered_html.
Affected Products
- OTP Login & Register WooCommerce plugin (mobile-login-woocommerce) for WordPress
- All versions up to and including 2.7.3
- WordPress multisite installations where the plugin is active
Discovery Timeline
- 2026-09-19 - CVE-2026-12402 published to the National Vulnerability Database
- 2026-09-21 - Last updated in the NVD database
Technical Details for CVE-2026-12402
Vulnerability Analysis
The vulnerability is a Stored Cross-Site Scripting weakness in the plugin's fb-config administrative setting. The plugin accepts input submitted through the admin settings interface but fails to sanitize the value on write and fails to escape it on output. As a result, attacker-controlled markup persists in the WordPress database and renders directly within page context.
Exploitation requires authenticated access at the administrator level or higher. Once an attacker injects a payload, the script executes whenever a visitor loads a page containing the affected setting output. In multisite deployments, WordPress restricts the unfiltered_html capability for site administrators. This creates a privilege boundary that the vulnerable setting bypasses, allowing a site administrator to plant script content that executes in the super administrator's session.
Root Cause
The root cause is missing input sanitization and missing output escaping around the fb-config setting handled by the plugin. The relevant handlers appear in class-xoo-ml-frontend.php and the framework admin settings class class-xoo-admin-settings.php. WordPress provides APIs such as sanitize_text_field(), wp_kses(), and esc_html()/esc_attr() for these boundaries, but the affected code paths do not apply them to the setting value.
Attack Vector
An authenticated administrator submits a crafted value containing JavaScript to the plugin's settings page. The payload is stored in WordPress options and later rendered without escaping in front-end or admin output. Any user, including a network super administrator, executes the script when accessing the injected page. See the Wordfence Vulnerability Report and the WordPress Plugin Class File for the vulnerable code locations.
No verified public exploit code is available. The vulnerability mechanism follows the standard stored XSS pattern: unsanitized administrator input written to persistent storage, then reflected without escaping into HTML output rendered in another user's browser.
Detection Methods for CVE-2026-12402
Indicators of Compromise
- Unexpected <script> tags, event handlers (for example onerror=, onload=), or javascript: URIs stored in the plugin's fb-config option value within the WordPress wp_options table.
- Outbound requests from browser sessions of administrators or super administrators to unknown domains after visiting plugin-controlled pages.
- Recent modifications to plugin settings by lower-privileged administrator accounts on multisite installations.
Detection Strategies
- Query the WordPress database for plugin-related option rows and inspect values for HTML or JavaScript content that should not appear in a configuration field.
- Review WordPress audit logs for update_option events targeting the OTP Login & Register WooCommerce plugin settings, especially from site administrator accounts on multisite installations.
- Deploy Content Security Policy (CSP) reporting to surface inline script execution originating from WordPress admin or WooCommerce pages.
Monitoring Recommendations
- Alert on administrator logins from atypical IP addresses or user agents that precede plugin setting changes.
- Monitor WordPress plugin version inventory and flag hosts still running mobile-login-woocommerce version 2.7.3 or earlier.
- Correlate super administrator browser sessions with unexpected DOM modifications or network callbacks on multisite estates.
How to Mitigate CVE-2026-12402
Immediate Actions Required
- Update the OTP Login & Register WooCommerce plugin to the patched release published after 2.7.3 as tracked in the WordPress Changeset Update.
- Audit the plugin's stored settings for injected script content and remove any suspicious values before restoring normal operation.
- Rotate credentials for any administrator or super administrator account whose browser session may have executed injected script.
Patch Information
The vendor addressed the vulnerability in a version released after 2.7.3. Refer to the WordPress Changeset Update for the specific commit and the Wordfence Vulnerability Report for the fixed version details.
Workarounds
- Restrict administrator-level access on multisite installations to trusted operators only until the patch is applied.
- Deploy a Web Application Firewall rule that blocks HTML and JavaScript payloads submitted to the plugin's settings endpoints.
- Enforce a strict Content Security Policy that disallows inline scripts on WordPress admin and front-end pages to reduce stored XSS impact.
# Update the plugin via WP-CLI once a patched version is available
wp plugin update mobile-login-woocommerce
# Verify the installed version is above 2.7.3
wp plugin get mobile-login-woocommerce --field=version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
