Impact
The Clean Login WordPress plugin version < 1.19 contains a flaw that does not verify whether user registration is enabled before creating a new account. An unauthenticated user can invoke the registration handler and obtain a new user account on the site. This allows an attacker to create multiple accounts, potentially using them for spam, phishing, or to gain access to privileged content if the new account is granted higher roles, thereby compromising confidentiality, integrity, and availability of the website. The weakness is a classic improper access control (CWE‑284).
Affected Systems
Affected systems are websites that use the Clean Login plugin before version 1.19. The plugin can be found under the vendor label “Unknown:Clean Login” in CVE listings. No other vendors or products are listed, so the vulnerability applies only to installations that have this specific plugin version.
Risk and Exploitability
With a CVSS score of 5.3 the severity is moderate, and the EPSS score indicates a very low exploitation likelihood (<1%). The vulnerability is not listed in the CISA KEV catalog. Attackers would need to send a malicious request to the plugin’s registration endpoint, which is accessible over HTTP and does not require prior authentication. While not a high‑profile vector, the ability to create arbitrary accounts can be leveraged in phishing or automated attacks if an attacker can find ways to promote these accounts.
OpenCVE Enrichment