Published: January 31, 2020 CVE number: CVE-2019-20173 Credit: Muhamad VisatDocumentation Index
Fetch the complete documentation index at: https://docs-staging.auth0-mintlify.app/llms.txt
Use this file to discover all available pages before exploring further.
Overview
The WordPress Plugin for Auth0 versions 3.11.0, 3.11.1, and 3.11.2 do not properly sanitize thewle query parameter. This could allow an attacker to run a cross-site scripting (XSS) attack on the login page.
Am I affected?
You are affected by this vulnerability if all of the following apply:- You are using the WordPress Plugin for Auth0 versions 3.11.0, 3.11.1, or 3.11.2
-
The “Original Login Form on wp-login.php” setting under Basic settings is set to either of the two options:
- “Via a link under the Auth0 form” (default option)
- “When “wle” query parameter is present”