CVE-2026-90976

Summary

The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an account in its registration handler, allowing unauthenticated users to create accounts even when the site has registration disabled.

Affected Software

VendorProductVersion RangeStatus
UnknownClean Login0 < 1.19affected

Weaknesses

  • CWE-284 Improper Access Control

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References