Auth0 WordPress Plugin
cpe:2.3:a:auth0:wp-auth0:*:*:*:*:wordpress:*:*
- <= 3.11.3
A cross-site request forgery (CSRF) vulnerability has been identified in the Auth0 WordPress plugin, affecting versions prior to 4.0.0. The vulnerability arises in the domain field, where the plugin lacks proper CSRF controls, allowing unauthorized actions to be performed on behalf of the user.
Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of the user, potentially allowing attackers to manipulate settings or data within the WordPress site.
Users are advised to upgrade to Auth0 WordPress Plugin version 4.0.0 or later. The release notes and migration instructions are available on the plugin's GitHub repository.