VYPR

WordPress

by Auth0

Source repositories

CVEs (2)

  • CVE-2023-6813MedJul 10, 2024
    risk 0.40cvss 6.1epss 0.00

    The Login by Auth0 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wle’ parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2025-68129MedDec 17, 2025
    risk 0.37cvss 6.8epss 0.00

    Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is performed improperly. Without proper validation, affected applications may accept ID tokens as Access tokens. Projects…