Executive brief
The Clean Login plugin for WordPress, which provides front-end login and registration forms, contains a security flaw that allows unauthorized users to manipulate data. An attacker could exploit this to bypass security checks and potentially modify information or disrupt site operations without needing a password. This could lead to unauthorized changes to user accounts or site settings, impacting the integrity and availability of the website.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the Clean Login plugin for WordPress (versions <= 1.15) due to insufficient authorization checks on user-controlled keys. An unauthenticated remote attacker can exploit this flaw by sending crafted network requests to manipulate objects they should not have access to. According to the CVSS vector, the primary impact is on integrity and availability, suggesting an attacker can modify data or cause a denial-of-service condition. The vulnerability is addressed in version 1.16.
Affected products
- Alberto Hornero Clean Login <= 1.15
Timeline
- 2026-04-21: other: Reported by Jakub Herman
- 2026-06-16: advisory: Patchstack advisory published
- 2026-06-17: disclosed: NVD publication date
- 2026-06-17: patched: Version 1.16 released