First published: Wed Feb 05 2020(Updated: )
The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Auth0 Login By Auth0 | >=3.11.0<3.11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20173 has a medium severity rating due to its potential for XSS attacks.
To fix CVE-2019-20173, update the Auth0 wp-auth0 plugin to version 3.11.3 or later.
CVE-2019-20173 is classified as a Cross-Site Scripting (XSS) vulnerability.
The affected versions of the Auth0 plugin are 3.11.0 to 3.11.2.
CVE-2019-20173 occurs in the wp-login.php file related to the wle parameter.