OktaOKTA-1GOPXBX
Improper File Type Handling in Bulk User Import in Auth0 Wordpress plugin CVE-2025-58769...
UnratedCVE-2025-58769 · Published Oct 1, 2025
In applications built with the Auth0-PHP SDK, the Bulk User Import endpoint does not validate the file path wrapper or value. To remediate, upgrade Auth0 Wordpress plugin to version 5.4.0 or greater.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 102025 | Race condition in the Okta Java SDK CVE-2025-67505 - Dec 10, 2025 | Unrated | No fix yet |
| Dec 102025 | Improper Memory Cleanup in the Okta Java SDK CVE-2025-66033 - Dec 10, 2025 | Unrated | No fix yet |
| Dec 102025 | Improper Request Caching Lookup in the Auth0 Next.js SDK CVE-2025-67490 - Dec 10, 2025 | Unrated | No fix yet |
| Dec 102025 | Improper Validation of Query Parameters in Auth0 Next.js SDK CVE-2025-67716 - Dec 10, 2025 | Unrated | No fix yet |
| Dec 42025 | Improper HMAC Signature Verification in auth0/node-jws CVE-2025-65945 - Dec 4, 2025 | Unrated | No fix yet |
| Jul 222025 | Okta On-Premises Provisioning (OPP) Password Reset Information Disclosure CVE-2025-7371... | Unrated | No fix yet |