VYPR

Login By Auth0

by Auth0

CVEs (4)

  • CVE-2020-7947CriApr 1, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting…

  • CVE-2020-7948HigApr 1, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. A user can perform an insecure direct object reference.

  • CVE-2020-6753MedApr 1, 2020
    risk 0.40cvss 6.1epss 0.01

    The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-2020-5392.

  • CVE-2019-20173MedFeb 5, 2020
    risk 0.40cvss 6.1epss 0.02

    The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.