Medium severity5.3NVD Advisory· Published Sep 18, 2026
CVE-2026-90977
CVE-2026-90977
Description
The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.19
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.