Login by Auth0 <= 3.11.3 - Cross-Site Request Forgery
2020-04-01 00:00
Muhamad VisatStrategic Overview
StatusPatched in 4.0.0
Affected PluginLogin by Auth0
Affected Version
<= 3.11.3CVSS8.8High
CVE
CVE-2020-5391Vulnerability Overview
Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.
Technical Analysis
REMEDIATION: Update to version 4.0.0, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C