WordPress Plugin Vulnerabilities
Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison
Description
The plugin does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Arthur Morgan
Submitter
Arthur Morgan
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-16 (about 2 days ago)
Added
2026-09-16 (about 1 day ago)
Last Updated
2026-09-16 (about 1 day ago)