{"id":"CVE-2019-20173","details":"The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.","modified":"2026-04-10T04:17:03.184491Z","published":"2020-02-05T20:15:11.030Z","references":[{"type":"ADVISORY","url":"https://auth0.com/docs/security/bulletins/cve-2019-20173"},{"type":"ADVISORY","url":"https://github.com/auth0/wp-auth0/releases/tag/3.11.3"},{"type":"ADVISORY","url":"https://wpvulndb.com/vulnerabilities/10059"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/auth0/wordpress","events":[{"introduced":"0"},{"fixed":"8f60b5b058daf5c512b66d525e025a19599f326f"}]},{"type":"GIT","repo":"https://github.com/auth0/wp-auth0","events":[{"introduced":"1a3c1dd024d988be052b37cdc395f9f58b0e0eb4"},{"fixed":"8f60b5b058daf5c512b66d525e025a19599f326f"}],"database_specific":{"versions":[{"introduced":"3.11.0"},{"fixed":"3.11.3"}]}}],"versions":["1.2.1","1.2.2","1.2.3","1.2.4","1.2.7","1.3.0","1.3.1","1.3.6","2.0.0","2.1.0","2.1.1","2.1.11","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","2.2.0","3.1.1","3.1.2","3.1.3","3.11.1","3.11.2","3.2.0","3.2.10","3.2.14","3.2.19","3.2.25","3.2.5","3.2.8","3.2.9","3.4.0","3.6.0","3.6.1","3.6.2","3.7.0","3.7.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20173.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}