VendorsAuth0wp-auth0all versions
Vulnerabilities

Auth0 wp-auth0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2020-5391
Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.
Published 2020-04-01 · Modified
8.8EPSS 0.008
CVE-2025-68129
Auth0-PHP SDK has Improper Audience Validation
Published 2025-12-17 · Analyzed
7.5EPSS 0.004
CVE-2020-5392
A stored cross-site scripting (XSS) vulnerability exists in the Auth0 plugin before 4.0.0 for WordPress via the settings page.
Published 2020-04-01 · Modified
6.1EPSS 0.013