Auth0 WordPress Plugin has Insufficient Entropy in Cookie Encryption
Package
Affected versions
>= 5.0.0-BETA0, <= 5.5.0
Patched versions
5.6.0
Description
Published to the GitHub Advisory Database
Apr 3, 2026
Reviewed
Apr 3, 2026
Impact
In applications built with the Auth0 PHP SDK, cookies are encrypted with insufficient entropy, which may result in threat actors brute-forcing the encryption key and forging session cookies.
Am I Affected?
Consumers are affected if their application meets the following preconditions:
Resolution
Upgrade Auth0/wordpress to version 5.6.0 or greater.
References