CVE-2020-7947
Last modified
CVE-2020-7947 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. EPSS estimates a 2.84% chance of exploitation in the next 30 days.
Description
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting of the user data. This can lead to (at least) CSV injection if a crafted Excel document is uploaded.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Auth0 | Login By Auth0 | < 4.0.0 |
References
- https://auth0.com/docs/cms/wordpressProduct, Vendor Advisory
- https://auth0.com/docs/security/bulletins/2020-03-31_wpauth0Third Party Advisory
- https://github.com/auth0/wp-auth0/security/advisories/GHSA-59vf-cgfw-6h6vThird Party Advisory
- https://wordpress.org/plugins/auth0/#developersRelease Notes, Third Party Advisory
- https://auth0.com/docs/cms/wordpressProduct, Vendor Advisory
- https://auth0.com/docs/security/bulletins/2020-03-31_wpauth0Third Party Advisory
- https://github.com/auth0/wp-auth0/security/advisories/GHSA-59vf-cgfw-6h6vThird Party Advisory
- https://wordpress.org/plugins/auth0/#developersRelease Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7947?
How severe is CVE-2020-7947?
How do I fix CVE-2020-7947?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-7940Missing password strength checks on some forms in Plone 4.3 …7.5
- CVE-2020-7941A privilege escalation issue in plone.app.contenttypes in Pl…9.8
- CVE-2020-7942Previously, Puppet operated on a model that a node with a va…6.5
- CVE-2020-7943Puppet Server and PuppetDB provide useful performance and de…7.5
- CVE-2020-7944In Continuous Delivery for Puppet Enterprise (CD4PE) before …7.7
- CVE-2020-7945Local registry credentials were included directly in the CD4…5.5
- CVE-2020-7948An issue was discovered in the Login by Auth0 plugin before …8.8
- CVE-2020-7949schemasystem.dll in Valve Dota 2 before 7.23f allows remote …7.8
- CVE-2020-7950meshsystem.dll in Valve Dota 2 before 7.23f allows remote at…7.8
- CVE-2020-7951meshsystem.dll in Valve Dota 2 before 7.23e allows remote at…7.8
- CVE-2020-7952rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remo…7.8
- CVE-2020-7953An issue was discovered in OpServices OpMon 9.3.2. Without a…7.5
Are you affected by CVE-2020-7947?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
