CVE-2026-90977
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Sep 18, 2026
Vendor
unknown
Description
The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.