Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-90976 | 1 Wordpress-extensions | 1 Clean Login | 2026-09-28 | 5.3 Medium |
| The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an account in its registration handler, allowing unauthenticated users to create accounts even when the site has registration disabled. | ||||
| CVE-2026-90977 | 1 Wordpress-extensions | 1 Clean Login | 2026-09-28 | 5.3 Medium |
| The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it. | ||||
Page 1 of 1.