The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it. This vulnerability affects WordPress installations using the Clean Login plugin, potentially allowing unauthorized account creation. Defenders shoul [truncated]
CVE-2026-90976 is a vulnerability in the Clean Login WordPress plugin before version 1.19 that allows unauthenticated users to create accounts even when the site has registration disabled. This issue has a CVSS score of 5.3 and is considered medium severity. The vulnerability impacts WordPress sites using the Clean Login plugin, as it allows unauthorized account creation, potentially leading to security b [truncated]