medium · CVSS v3 5.3 · EPSS 0.00272
CVE-2026-90977
The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is e…
Description
The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- 0.00272