GHSA-vm4x-47jq-gqccMediumCVSS 5.3

The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled...

Published
September 18, 2026
Last Modified
September 18, 2026

🔗 CVE IDs covered (1)

📋 Description

The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an account in its registration handler, allowing unauthenticated users to create accounts even when the site has registration disabled.

🔗 References (3)