Vulnerabilities (CVE)

Filtered by vendor Auth0 Subscribe
Filtered by product Wp-auth0
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-5392 1 Auth0 1 Wp-auth0 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability exists in the Auth0 plugin before 4.0.0 for WordPress via the settings page.
CVE-2020-5391 1 Auth0 1 Wp-auth0 2024-02-04 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.