ExploitMatch
Back

CVE-2026-90977

Monitor on ThreatCluster

Description

The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.