Overview
The WordPress Plugin for Auth0 versions 3.11.0, 3.11.1, and 3.11.2 do not properly sanitize thewle query parameter. This could allow an attacker to run a cross-site scripting (XSS) attack on the login page.
Am I affected?
You are affected by this vulnerability if all of the following apply:- You are using the WordPress Plugin for Auth0 versions 3.11.0, 3.11.1, or 3.11.2
-
The âOriginal Login Form on wp-login.phpâ setting under Basic settings is set to either of the two options:
- âVia a link under the Auth0 formâ (default option)
- âWhen âwleâ query parameter is presentâ