PT-2020-19866 · Auth0 · Login By Auth0 Plugin For Wordpress

Muhamad Visat

·

Published

2020-04-01

·

Updated

2021-07-21

·

CVE-2020-7947

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Login by Auth0 plugin for WordPress versions prior to 4.0.0
Description The issue arises from the plugin's failure to sanitize and validate data from various sources before exporting user data. This oversight can lead to CSV injection attacks if a maliciously crafted Excel document is uploaded.
Recommendations For versions prior to 4.0.0, update to version 4.0.0 or later to resolve the issue. As a temporary workaround, consider restricting the upload of Excel documents or implementing additional validation and sanitization of user data before export.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7947
GHSA-59VF-CGFW-6H6V

Affected Products

Login By Auth0 Plugin For Wordpress