CVE-2020-6753: XSS
Published Apr 1, 2020
·Updated
The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-2020-5392.
Affected Software
1 affected component
Auth0 Login By Auth0 Wordpress<4.0.0
Event History
Apr 1, 2020
CVE Published
via MITRE·12:49 PM
Data Sourced
via MITRE·12:49 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-6753?
CVE-2020-6753 is classified as a medium severity vulnerability due to the potential for stored XSS attacks.
2
How do I fix CVE-2020-6753?
To fix CVE-2020-6753, update the Login by Auth0 plugin to version 4.0.0 or higher.
3
What is stored XSS in relation to CVE-2020-6753?
Stored XSS in CVE-2020-6753 allows attackers to inject malicious scripts that can be executed when other users visit affected pages.
4
Which versions of the Login by Auth0 plugin are affected by CVE-2020-6753?
CVE-2020-6753 affects all versions of the Login by Auth0 plugin before version 4.0.0.
5
Where can I find more information about CVE-2020-6753?
More information about CVE-2020-6753 can be found in the official Auth0 security bulletins and GitHub repositories.