Description
The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Account Creation via CAPTCHA Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated user to create a WordPress account without completing the CAPTCHA step. The plugin fails to verify the stored session CAPTCHA value when it is empty, enabling a bypass that could lead to automated account creation and subsequent spam or abuse. The problem manifests as a logic flaw where two different types of values are improperly compared, as described by CWE-697.

Affected Systems

Any WordPress installation using the Clean Login plugin version earlier than 1.19 is affected. The plugin is not tied to a broader vendor line; it is a third‑party add‑on that can be found under the Unknown:Clean Login identifier. No specific version range is listed beyond the cutoff at 1.19, so any pre‑1.19 release is vulnerable.

Risk and Exploitability

The reported CVSS score of 5.3 indicates medium impact, and the EPSS score of less than 1% signals low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, which further suggests limited known activity. The likely attack path requires only unauthenticated access to the registration form and reliance on the empty session bug, making the threat accessible to any attacker who can submit form data. The risk emerges primarily from the ability to create accounts wholesale, which could be exploited for spam, phishing, or to bypass other site controls that rely on valid registrations.

Generated by OpenCVE AI on September 19, 2026 at 19:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Clean Login plugin to version 1.19 or later to remove the CAPTCHA bypass flaw.
  • If an immediate upgrade is not feasible, temporarily disable public user registration or replace the current CAPTCHA mechanism with a version that performs session value verification.
  • Audit the active registration process and ensure that any session or CAPTCHA data is mandatory before account creation to prevent automated abuse.

Generated by OpenCVE AI on September 19, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions clean Login
Vendors & Products Wordpress-extensions
Wordpress-extensions clean Login

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-697
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.
Title Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordpress-extensions Clean Login
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T10:59:55.405Z

Reserved: 2026-09-14T13:40:30.252Z

Link: CVE-2026-90977

cve-icon Vulnrichment

Updated: 2026-09-18T10:53:03.219Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:51.590

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-90977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:50Z

Weaknesses