PT-2020-18450 · Auth0 · Auth0 Plugin For Wordpress

Mattmarji

·

Published

2020-04-01

·

Updated

2020-04-01

·

CVE-2020-5391

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Auth0 plugin for WordPress versions prior to 4.0.0
Description The issue is related to cross-site request forgery (CSRF) vulnerabilities. These vulnerabilities exist in the Auth0 plugin for WordPress, specifically via the domain field.
Recommendations For versions prior to 4.0.0, update to version 4.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the domain field to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5391
GHSA-59VF-CGFW-6H6V

Affected Products

Auth0 Plugin For Wordpress