WordPress Plugin Vulnerabilities

Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison

Description

The plugin does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.

Proof of Concept

Affects Plugins

Fixed in 1.19

References

Miscellaneous

Original Researcher
Arthur Morgan
Submitter
Arthur Morgan
Verified
Yes

Timeline

Publicly Published
2026-09-16 (about 2 days ago)
Added
2026-09-16 (about 1 day ago)
Last Updated
2026-09-16 (about 1 day ago)

Other