CVE-2026-90977 Details
Description
The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.
A vulnerability exists in the Clean Login WordPress plugin in versions prior to 1.19, where the registration CAPTCHA is not validated if the session value is empty. This flaw allows unauthenticated users to bypass the CAPTCHA requirement on the registration form, enabling them to create accounts without completing the CAPTCHA challenge.
Users are advised to update the Clean Login WordPress plugin to version 1.19 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 18, 2026CISA-ADP
Assessed Sep 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/368db83e-ed7b-4f67-99db-2e5f1c01568e/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-697 | Incorrect Comparison | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Clean Login | < 1.19 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | CVE Modified | CISA-ADP |
| Sep 18, 2026 | New CVE Received | [email protected] |
Volerion