← WordPress Vulnerabilities
WordPress security by component

Login by Auth0

Login by Auth0 is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 10, 2024; the highest CVE/CNA score is 6.1.

Plugin slug: login-by-auth0

CVE-2023-6813: Login by Auth0: Cross-site scripting

Login by Auth0 is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedJul 10, 2024
Safe version guidanceSee mitigation notes
Safe version
Jul 10, 2024 CVE-2023-6813
Login by Auth0: Cross-site scripting
Login by Auth0 is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Apr 01, 2020 CVE-2020-6753
Login By Auth0: Cross-site scripting
Login By Auth0 is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Feb 05, 2020 CVE-2019-20173
Login By Auth0: Cross-site scripting
Login By Auth0 is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1