CVE-2019-20173: AUTH0 Login By AUTH0
Medium severity, CVSS 6.1. EPSS: 2.5% chance of exploitation in the next 30 days.
The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.
Affected products
- AUTH0 Login By AUTH0: from 3.11.0, before 3.11.3 (fixed in 3.11.3)
Published 2020-02-05. Last modified 2026-06-17.