Description
The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an account in its registration handler, allowing unauthenticated users to create accounts even when the site has registration disabled.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Account Creation
Action: Update Plugin
AI Analysis

Impact

The Clean Login WordPress plugin version < 1.19 contains a flaw that does not verify whether user registration is enabled before creating a new account. An unauthenticated user can invoke the registration handler and obtain a new user account on the site. This allows an attacker to create multiple accounts, potentially using them for spam, phishing, or to gain access to privileged content if the new account is granted higher roles, thereby compromising confidentiality, integrity, and availability of the website. The weakness is a classic improper access control (CWE‑284).

Affected Systems

Affected systems are websites that use the Clean Login plugin before version 1.19. The plugin can be found under the vendor label “Unknown:Clean Login” in CVE listings. No other vendors or products are listed, so the vulnerability applies only to installations that have this specific plugin version.

Risk and Exploitability

With a CVSS score of 5.3 the severity is moderate, and the EPSS score indicates a very low exploitation likelihood (<1%). The vulnerability is not listed in the CISA KEV catalog. Attackers would need to send a malicious request to the plugin’s registration endpoint, which is accessible over HTTP and does not require prior authentication. While not a high‑profile vector, the ability to create arbitrary accounts can be leveraged in phishing or automated attacks if an attacker can find ways to promote these accounts.

Generated by OpenCVE AI on September 19, 2026 at 19:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Clean Login plugin to version 1.19 or newer, which includes proper registration checks.
  • Disable user registration in the WordPress settings or restrict registration to approved emails if the website does not support new user creation.
  • Monitor and audit new user accounts, and remove any suspicious or automated registrations.

Generated by OpenCVE AI on September 19, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions clean Login
Vendors & Products Wordpress-extensions
Wordpress-extensions clean Login

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an account in its registration handler, allowing unauthenticated users to create accounts even when the site has registration disabled.
Title Clean Login < 1.19 - Unauthenticated Account Creation with Registration Disabled
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress-extensions Clean Login
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T10:59:55.567Z

Reserved: 2026-09-14T13:40:23.363Z

Link: CVE-2026-90976

cve-icon Vulnrichment

Updated: 2026-09-18T10:53:05.400Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:51.473

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-90976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:52Z

Weaknesses