Clean Login <= 1.15 - Unauthenticated Insecure Direct Object Reference
medium
The Clean Login plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.15 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.15
- Fixed in:
- 1.16
- Disclosed:
- Jun 16, 2026
CVE-2026-54184 on NVD →
Clean Login [clean-login] < 1.14.6
unknown
[en] The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary f...
- Affected:
- up to 1.14.6
- Fixed in:
- 1.14.6
- Disclosed:
- Aug 30, 2024
CVE-2024-8252 on NVD →
Clean Login <= 1.14.5 - Authenticated (Contributor+) Local File Inclusion
high
The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files...
- CVSS:
- 8.8
- Affected:
- up to 1.14.5
- Fixed in:
- 1.14.6
- Disclosed:
- Aug 29, 2024
CVE-2024-8252 on NVD →
Clean Login [clean-login] < 1.13.7
unknown
[en] The Clean Login WordPress plugin before 1.13.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as adm...
- Affected:
- up to 1.13.7
- Fixed in:
- 1.13.7
- Disclosed:
- Feb 6, 2023
CVE-2022-4838 on NVD →
Clean Login <= 1.13.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Clean Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and abo...
- CVSS:
- 6.4
- Affected:
- up to 1.13.6
- Fixed in:
- 1.13.7
- Disclosed:
- Jan 10, 2023
CVE-2022-4838 on NVD →
Clean Login 1.12.6.3 - Cross-Site Scripting
medium
The Clean Login for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in version 1.12.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- 1.12.6.3 – 1.12.6.3
- Fixed in:
- 1.12.6.4
- Disclosed:
- Aug 9, 2021
Clean Login [clean-login] < 1.12.6.4
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Clean Login plugin (versions <= 1.12.6.3).
- Affected:
- up to 1.12.6.4
- Fixed in:
- 1.12.6.4
- Disclosed:
- Aug 9, 2021
Clean Login [clean-login] < 1.12.6.4
unknown
The Clean Login for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in version 1.12.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- Affected:
- up to 1.12.6.4
- Fixed in:
- 1.12.6.4
- Disclosed:
- Aug 9, 2021
Clean Login <= 1.10.3 - Cross-Site Request Forgery
high
The Clean Login for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.3. This is due to missing or incorrect nonce validation on the clean_login_options() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request grante...
- CVSS:
- 8.8
- Affected:
- up to 1.10.3
- Fixed in:
- 1.10.4
- Disclosed:
- Jun 29, 2020
CVE-2017-8875 on NVD →
Clean Login [clean-login] < 1.5.1
unknown
[en] The clean-login plugin before 1.5.1 for WordPress has reflected XSS.
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.1
- Disclosed:
- Aug 22, 2019
CVE-2015-9336 on NVD →
Clean Login [clean-login] < 1.10.4
unknown
[en] CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.
- Affected:
- up to 1.10.4
- Fixed in:
- 1.10.4
- Disclosed:
- May 10, 2017
CVE-2017-8875 on NVD →
Clean Login <= 1.5 - Reflected Cross-Site Scripting
medium
The Clean Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on the 'pass' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...
- CVSS:
- 6.1
- Affected:
- up to 1.5
- Fixed in:
- 1.5.1
- Disclosed:
- Jul 27, 2015
CVE-2015-9336 on NVD →
Clean Login [clean-login] < 1.12.6.4
unknown
The plugin does not escape the url parameter in its login form page, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 1.12.6.4
- Fixed in:
- 1.12.6.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database