Auth0 Plugin for WordPress < 4.0.0 Multiple Vulnerabilities

high Web App Scanning Plugin ID 113470

Synopsis

Auth0 Plugin for WordPress < 4.0.0 Multiple Vulnerabilities

Description

The WordPress Auth0 Plugin installed on the remote host is affected by multiple Stored Cross-Site Scripting and a Cross-site Request Forgery.

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Auth0 Plugin for WordPress 4.0.0 or latest.

See Also

https://wordpress.org/plugins/auth0/

Plugin Details

Severity: High

ID: 113470

Type: remote

Published: 12/27/2022

Updated: 3/14/2023

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2020-5391

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2020-5391

Vulnerability Information

CPE: cpe:2.3:a:auth0:login_by_auth0:*:*:*:*:*:wordpress:*:*

Exploit Ease: No known exploits are available

Patch Publication Date: 4/1/2020

Vulnerability Publication Date: 4/1/2020

Reference Information

CVE: CVE-2020-5391, CVE-2020-5392, CVE-2020-6753