VYPR

wp-auth0

by Auth0

Source repositories

CVEs (4)

  • CVE-2020-5391HigApr 1, 2020
    risk 0.50cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.

  • CVE-2019-20173MedFeb 5, 2020
    risk 0.40cvss 6.1epss 0.02

    The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.

  • CVE-2025-68129MedDec 17, 2025
    risk 0.37cvss 6.8epss 0.00

    Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is performed improperly. Without proper validation, affected applications may accept ID tokens as Access tokens. Projects…

  • CVE-2020-5392MedApr 1, 2020
    risk 0.33cvss 6.1epss 0.01

    A stored cross-site scripting (XSS) vulnerability exists in the Auth0 plugin before 4.0.0 for WordPress via the settings page.