PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-54184 Alberto Hornero CVE debrief

CVE-2026-54184 is a HIGH-severity vulnerability (CVSS Score: 8.2) in the Clean Login plugin, affecting versions up to 1.15. This Unauthenticated Insecure Direct Object References (IDOR) vulnerability allows attackers to manipulate object references, potentially leading to unauthorized data access or modification. The vulnerability was published on June 17, 2026, and immediately gained attention due to its high severity and potential impact on WordPress sites using the Clean Login plugin. Users of the Clean Login plugin should update to the latest version to mitigate this risk.

Vendor
Alberto Hornero
Product
Clean Login
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-06-17
Advisory published
2026-06-17
Advisory updated
2026-06-17

Who should care

Administrators and security teams responsible for WordPress installations using the Clean Login plugin, especially those on version 1.15 or lower, should prioritize updating the plugin to prevent potential exploitation.

Technical summary

CVE-2026-54184 is an Unauthenticated Insecure Direct Object References (IDOR) vulnerability in the Clean Login plugin for WordPress. The vulnerability has a CVSS Score of 8.2, indicating high severity. It allows unauthenticated attackers with network access to manipulate object references, potentially leading to data integrity impacts. The vulnerability is characterized by the following CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H. This indicates that the vulnerability can be exploited over the network (AV:N), requires low attack complexity (AC:L), does not require any privileges (PR:N), and has a high impact on availability (A:H) and low impact on integrity (I:L).

Defensive priority

High

Recommended defensive actions

  • Update the Clean Login plugin to the latest version immediately.
  • Review and restrict access to sensitive data and functionality within WordPress installations using the Clean Login plugin.
  • Implement additional security measures such as Web Application Firewalls (WAFs) to detect and prevent exploitation attempts.
  • Regularly monitor WordPress installations and plugins for updates and security advisories.
  • Consider replacing the Clean Login plugin with alternative authentication solutions if updating is not feasible.
  • Enhance logging and monitoring to detect potential exploitation attempts.

Evidence notes

The CVE details were sourced from the official CVE record (resourceLinkAnnotations: cve-org) and the National Vulnerability Database (resourceLinkAnnotations: nvd). Additional information was obtained from Patchstack (resourceLinkAnnotations: ref-4), which reported the vulnerability.

Official resources

CVE-2026-54184 was published on June 17, 2026, and last modified on June 17, 2026.