Executive brief
Clean Login is a WordPress plugin that manages user registration and login forms. The plugin fails to validate its anti-spam CAPTCHA control when certain session values are missing, allowing attackers to automatically create fake user accounts on WordPress sites without solving the CAPTCHA challenge. This can lead to account enumeration, spam, and unauthorized access to the affected WordPress installation.
Technical details
The vulnerability is a CAPTCHA bypass flaw in the Clean Login WordPress plugin's registration form validation logic. The plugin fails to verify the CAPTCHA solution when the corresponding session value is empty or missing, resulting in insufficient input validation. No authentication is required—an unauthenticated attacker can directly submit a registration request with an empty or missing session value to bypass the CAPTCHA anti-automation control. An attacker can exploit this to programmatically create multiple fake user accounts, facilitating spam, phishing, or reconnaissance attacks. The vulnerability is fixed in version 1.19 and later.
Affected products
- Clean Login Clean Login before 1.19
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Fixed in version 1.19