rootpwn

medium · CVSS v3 5.3 · EPSS 0.00272

CVE-2026-90977

The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is e…

Description

The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
EPSS
0.00272

← All CVEs