PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-90976 Clean Login CVE debrief

CVE-2026-90976 is a vulnerability in the Clean Login WordPress plugin before version 1.19 that allows unauthenticated users to create accounts even when the site has registration disabled. This issue has a CVSS score of 5.3 and is considered medium severity. The vulnerability impacts WordPress sites using the Clean Login plugin, as it allows unauthorized account creation, potentially leading to security breaches. Defenders should assess exposure and verify the version of the plugin to ensure it is 1.19 or later. They should also configure registration settings properly to prevent unauthorized account creation and monitor for unauthorized account creation activity.

Vendor
Clean Login
Product
Clean Login WordPress plugin
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-09-18
Advisory published
2026-09-18
Advisory updated
2026-09-18

Who should care

Defenders responsible for WordPress sites using the Clean Login plugin should assess exposure and verify the version of the plugin to ensure it is 1.19 or later. They should also configure registration settings properly to prevent unauthorized account creation and monitor for unauthorized account creation activity. This includes reviewing the plugin version, checking registration settings, and ensuring that security

Why it matters

CVE-2026-90976 is a medium-severity vulnerability in the Clean Login WordPress plugin that allows unauthenticated users to create accounts even when registration is disabled. Defenders responsible for WordPress sites using this plugin should assess exposure and take steps to prevent unauthorized account creation.

  • Defenders need to verify the version of the Clean Login WordPress plugin to ensure it is 1.19 or later.
  • Defenders should configure registration settings properly to prevent unauthorized account creation.
  • Defenders should monitor for unauthorized account creation activity.

Technical summary

The Clean Login WordPress plugin before version 1.19 does not check whether user registration is enabled before creating an account in its registration handler, allowing unauthenticated users to create accounts even when the site has registration disabled.

Defensive priority

Defenders should prioritize verifying the version of the Clean Login WordPress plugin and ensuring that registration is properly configured.

Recommended defensive actions

  • Verify the version of the Clean Login WordPress plugin
  • Ensure that registration is properly configured
  • Monitor for unauthorized account creation

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further investigation is needed to determine the full scope of the issue.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-90976 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-90976

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-90976 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90976

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.