CVE-2026-12402 | xootix OTP Login & Register WooCommerce Plugin up to 2.7.3 on WordPress Setting fb-config cross site scripting

SecurityVulns

A vulnerability was found in xootix OTP Login & Register WooCommerce Plugin up to 2.7.3 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Setting. The manipulation of the argument fb-config results in cross site scripting.

This vulnerability is known as CVE-2026-12402. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More