Impact
The vulnerability allows an unauthenticated user to create a WordPress account without completing the CAPTCHA step. The plugin fails to verify the stored session CAPTCHA value when it is empty, enabling a bypass that could lead to automated account creation and subsequent spam or abuse. The problem manifests as a logic flaw where two different types of values are improperly compared, as described by CWE-697.
Affected Systems
Any WordPress installation using the Clean Login plugin version earlier than 1.19 is affected. The plugin is not tied to a broader vendor line; it is a third‑party add‑on that can be found under the Unknown:Clean Login identifier. No specific version range is listed beyond the cutoff at 1.19, so any pre‑1.19 release is vulnerable.
Risk and Exploitability
The reported CVSS score of 5.3 indicates medium impact, and the EPSS score of less than 1% signals low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, which further suggests limited known activity. The likely attack path requires only unauthenticated access to the registration form and reliance on the empty session bug, making the threat accessible to any attacker who can submit form data. The risk emerges primarily from the ability to create accounts wholesale, which could be exploited for spam, phishing, or to bypass other site controls that rely on valid registrations.
OpenCVE Enrichment