Login by Auth0 <= 3.11.3 - Cross-Site Request Forgery

2020-04-01 00:00
Muhamad Visat

Strategic Overview

Status
Patched in 4.0.0
Affected PluginLogin by Auth0
Affected Version<= 3.11.3
CVSS8.8High
CVECVE-2020-5391
View all Login by Auth0 vulnerabilities

Vulnerability Overview

Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.

Technical Analysis

REMEDIATION: Update to version 4.0.0, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C