plugin

Auth0 Vulnerabilities

14 known security issues reported for the Auth0 WordPress plugin. Most recent disclosed Jul 10, 2024.

1 critical 2 high 4 medium

Running Auth0 on your site? Check whether your installed version is affected.

Scan your site free

Login by Auth0 [auth0] < 4.6.1

unknown

[en] The Login by Auth0 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wle’ parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

Affected:
up to 4.6.1
Fixed in:
4.6.1
Disclosed:
Jul 10, 2024

CVE-2023-6813 on NVD →

Login by Auth0 <= 4.6.0 - Reflected Cross-Site Scripting via wle

medium

The Login by Auth0 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wle’ parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...

CVSS:
6.1
Affected:
up to 4.6.0
Fixed in:
4.6.1
Disclosed:
Jul 9, 2024

CVE-2023-6813 on NVD →

Login by Auth0 <= 3.11.3 - CSV Injection

critical

An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting of the user data. This can lead to (at lea...

CVSS:
9.8
Affected:
up to 3.11.3
Fixed in:
4.0.0
Disclosed:
Apr 1, 2020

CVE-2020-7947 on NVD →

Login by Auth0 <= 3.11.3 - Cross-Site Request Forgery

high

Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.

CVSS:
8.8
Affected:
up to 3.11.3
Fixed in:
4.0.0
Disclosed:
Apr 1, 2020

CVE-2020-5391 on NVD →

Login by Auth0 <= 3.11.3 - Stored Cross-Site Scripting

high

The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-2020-5392.

CVSS:
7.2
Affected:
up to 3.11.3
Fixed in:
4.0.0
Disclosed:
Apr 1, 2020

CVE-2020-6753 on NVD →

Login by Auth0 <= 3.11.3 - Insecure Direct Object Reference

medium

An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. A user can perform an insecure direct object reference.

CVSS:
4.3
Affected:
up to 3.11.3
Fixed in:
4.0.0
Disclosed:
Apr 1, 2020

CVE-2020-7948 on NVD →

Login by Auth0 [auth0] < 4.0.0

unknown

[en] An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. A user can perform an insecure direct object reference.

Affected:
up to 4.0.0
Fixed in:
4.0.0
Disclosed:
Apr 1, 2020

CVE-2020-7948 on NVD →

Login by Auth0 [auth0] < 4.0.0

unknown

[en] The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-2020-5392.

Affected:
up to 4.0.0
Fixed in:
4.0.0
Disclosed:
Apr 1, 2020

CVE-2020-6753 on NVD →

Login by Auth0 [auth0] < 4.0.0

unknown

[en] Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.

Affected:
up to 4.0.0
Fixed in:
4.0.0
Disclosed:
Apr 1, 2020

CVE-2020-5391 on NVD →

Login by Auth0 [auth0] < 4.0.0

unknown

[en] A stored cross-site scripting (XSS) vulnerability exists in the Auth0 plugin before 4.0.0 for WordPress via the settings page.

Affected:
up to 4.0.0
Fixed in:
4.0.0
Disclosed:
Apr 1, 2020

CVE-2020-5392 on NVD →

Login by Auth0 [auth0] < 4.0.0

unknown

[en] An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting of the user data. This can lead to (a...

Affected:
up to 4.0.0
Fixed in:
4.0.0
Disclosed:
Apr 1, 2020

CVE-2020-7947 on NVD →

Login by Auth0 Plugin <= 3.11.3 - Stored Cross-Site Scripting

medium

The Login by Auth0 Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute wh...

CVSS:
5.5
Affected:
up to 3.11.3
Fixed in:
4.0.0
Disclosed:
Mar 31, 2020

CVE-2020-5392 on NVD →

Login by Auth0 [auth0] < 3.11.3

unknown

[en] The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.

Affected:
up to 3.11.3
Fixed in:
3.11.3
Disclosed:
Feb 5, 2020

CVE-2019-20173 on NVD →

Login by Auth0 3.11.0 - 3.11.2 - Cross-Site Scripting

medium

The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.

CVSS:
6.1
Affected:
3.11.0 – 3.11.2
Fixed in:
3.11.3
Disclosed:
Jan 31, 2020

CVE-2019-20173 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database