Auth0 Docs home page
Search...
⌘K
Ask AI
Log In
Contact Sales
Sign Up
Sign Up
Search...
Navigation
Security Bulletins
CVE-2019-20173: Security Update for WordPress Plugin for Auth0 wp-auth0
Documentation
Quickstarts
API Reference
SDKs
Secure
Make sure only the right people can access your applications
Secure
Protect Your Application
Application Credentials
Attack Protection
Continuous Session Protection
Highly Regulated Identity
Auth0’s Mobile Driver's License Verification Service
Multi-Factor Authentication
Security Center
Security Guidance
Overview
Security Guidance
General Security Tips
Security Bulletins
Overview
CVE-2022-23539, CVE-2022-23541, CVE-2022-23540: Security Update for jsonwebtoken
CVE-2022-23505: Security Update for passport-wsfed-saml2 Library
CVE-2022-24794: Security Update for Express OpenID Connect Library
CVE-2021-43812: Security Update for Next.js Auth0 Library
CVE-2021-41246: Security Update for Express OpenID Connect Library
CVE-2021-32702: Security Update for Auth0 Next.js Library
CVE-2021-32641: Security Update for Auth0 Lock Library
CVE 2020-15259: Security Update for ad-ldap-connector
CVE-2020-15240: Security Update for omniauth-auth0 JWT Validation
CVE-2020-15125: Security Update for node-auth0 Library
CVE-2020-15119: Security Update for Auth0 Lock Library
CVE-2020-15084: Security Update for express-jwt Library
CVE-2020-5391, CVE-2020-5392, CVE-2020-6753, CVE-2020-7948, CVE-2020-7947: Security Update for WordPress Plugin for Auth0
CVE-2020-5263: Security Update for auth0.js Library
CVE-2019-20174: Security Update for Auth0 Lock Library
CVE-2019-16929: Security Vulnerability in auth0.net
CVE-2019-13483: Security Vulnerability in Passport-SharePoint
CVE-2019-7644: Security Vulnerability in Auth0-WCF-Service-JWT
CVE-2019-20173: Security Update for WordPress Plugin for Auth0 wp-auth0
CVE-2018-15121: Security Vulnerability in auth0-aspnet and auth0-aspnet-owin
CVE-2018-11537: Security Update for angular-jwt Allow List Bypass
CVE-2018-7307: Security Vulnerability for auth0.js < 9.3
CVE-2018-6874: Security Vulnerability in the Auth0 Authentication Service
CVE-2018-6873: Security Vulnerability in the Auth0 Authentication Service
CVE-2017-17068: Security Update for auth0.js Popup Callback Vulnerability
CVE-2017-16897: Security Update for passport-wsfed-saml2 Passport Strategy Library
Auth0 Security Bulletin for Rules
Auth0 Security Bulletin for Assigning Scopes Based on Email Address
Data Security
Prevent Common Cybersecurity Threats
Incident Response: Using Logs
Sender Constraining
Tokens
Protect Your Tenant
Tenant Access Control List
Compliance
Data Privacy and Compliance
On this page
Overview
Am I affected?
How to fix that?
Will this update impact my users?
Protect Your Application
Security Guidance
Security Bulletins
CVE-2019-20173: Security Update for WordPress Plugin for Auth0 wp-auth0
Copy page
Copy page
Published
: January 31, 2020
CVE number
: CVE-2019-20173
Credit
: Muhamad Visat
Overview
The WordPress Plugin for Auth0 versions 3.11.0, 3.11.1, and 3.11.2 do not properly sanitize the
wle
query parameter. This could allow an attacker to run a cross-site scripting (XSS) attack on the login page.
Am I affected?
You are affected by this vulnerability if all of the following apply:
You are using the WordPress Plugin for Auth0 versions 3.11.0, 3.11.1, or 3.11.2
The “Original Login Form on wp-login.php” setting under Basic settings is set to either of the two options:
“Via a link under the Auth0 form” (default option)
“When “wle” query parameter is present”
How to fix that?
Developers using WordPress Plugin for Auth0 need to upgrade to version 3.11.3 or later.
Will this update impact my users?
No. This fix patches the library that your application runs, but will not impact your users, their current state, or any existing sessions.
Was this page helpful?
Yes
No
CVE-2019-7644: Security Vulnerability in Auth0-WCF-Service-JWT
Previous
CVE-2018-15121: Security Vulnerability in auth0-aspnet and auth0-aspnet-owin
Next
Assistant
Responses are generated using AI and may contain mistakes.