High severity8.8NVD Advisory· Published Apr 1, 2020· Updated Jun 17, 2026
CVE-2020-7948
CVE-2020-7948
Description
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. A user can perform an insecure direct object reference.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:auth0:login_by_auth0:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:auth0:login_by_auth0:*:*:*:*:*:wordpress:*:*range: <4.0.0
- (no CPE)range: <4.0.0
- WordPress/Login by Auth0description
- Range: <4.0.0
Patches
Vulnerability mechanics
References
4- auth0.com/docs/cms/wordpressnvdProductVendor Advisory
- auth0.com/docs/security/bulletins/2020-03-31_wpauth0nvdVendor Advisory
- github.com/auth0/wp-auth0/security/advisories/GHSA-59vf-cgfw-6h6vnvdThird Party Advisory
- wordpress.org/plugins/auth0/nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.