Login by Auth0
Login by Auth0 has 7 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2024; all 7 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 2 high. 2020 was the busiest year with 6 disclosures.
The most common weakness is Cross-Site Scripting, behind 4 of the records (57%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Cross-Site Request Forgery (CSRF).
Every one of the 7 issues recorded for Login by Auth0 has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (5) reported by Muhamad Visat. Login by Auth0 is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.
CVE-2020-7947Login by Auth0 <= 3.11.3 - CSV Injection
Read the full analysisVulnerability Records

Login by Auth0
Author
Auth0
This plugin replaces standard WordPress login forms with one powered by Auth0 that enables: Universal authentication Over 30 social login providers Enterprise connections (ADFS, Active Directory / LDAP, SAML, Office 365, Google Apps and more) Connect your own database Passwordless connections (using email or SMS) Ultra secure Multifactor authentication Password policies Email validation Mitigate brute force attacks Technical Notes IMPORTANT: By using this plugin you are delegating the site authentication and profile handling to Auth0. That means that you won’t be using the WordPress database to authenticate users and the default WordPress login forms will be replaced. Please see our How It Works page for more information on how Auth0 authenticates and manages your users. Migrating Existing Users Auth0 allows multiple authentication providers. You can have social providers like Facebook, Twitter, Google+, and more, a database of users and passwords (just like WordPress but hosted in Auth0), or you can use an Enterprise directory like Active Directory, LDAP, Office365, Google Apps, or SAML. All those authentication providers might give you an email and a flag indicating whether the email was verified or not. We use that email (only if it is verified) to associate a previous existing user with the one coming from Auth0. If the email was not verified and there is an account with that email in WordPress, the user will be presented with a page saying that the email was not verified and a link to “Re-send the verification email.” For either scenario, you can choose whether it is mandatory that the user has a verified email or not in the plugin settings. Please note: In order for a user to log in using Auth0, they will need to sign up via the Auth0 login form (or have an account created for them in Auth0). Once signup is complete, their Auth0 user will be automatically associated with their WordPress user. Widget You can enable Auth0 as a WordPress widget in order to show it in a sidebar. The widget inherits the main plugin settings but can be overridden with its own settings in the widget form. Note: this form will not display for logged-in users. Shortcode Also, you can use the Auth0 widget as a shortcode in your editor. Just add the following to use the global settings: [auth0] Like widgets, shortcode login forms will use the settings of the plugin. It can be customized by adding the following attributes: icon_url – A direct URL to an image used at the top of the login form form_title – Text to appear at the top of the login form gravatar – Display the user’s Gravatar; set to 1 for yes redirect_to – A direct URL to use after successful login dict – Valid JSON to override form text (see options here) extra_conf – Valid JSON to override Lock configuration (see options here) show_as_modal – Display a button that triggers the login form in a modal; set to 1 for yes modal_trigger_name – Button text to display when using a modal Example: [auth0 show_as_modal="1" modal_trigger_name="Login button: This text is configurable!"] Note: this form will not display for logged-in users.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C