CVE-2026-90977: Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison
The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
WordPress sites using the Clean Login plugin before version 1.19 are affected when its registration form and CAPTCHA anti-automation control are in use.
What does an attacker need to exploit it?
An attacker does not need authentication or user interaction. They can bypass the registration CAPTCHA when the plugin's stored session CAPTCHA value is empty.
What is the practical impact of exploitation?
An attacker can create accounts through the affected registration form without solving the CAPTCHA, undermining the form's anti-automation protection.
How can I determine whether my site is affected?
Check whether Clean Login is installed and whether its version is earlier than 1.19. Sites that expose the plugin's registration form are relevant to this issue.