plugin

Clean Login Vulnerabilities

13 known security issues reported for the Clean Login WordPress plugin. Most recent disclosed Jun 16, 2026.

2 high 4 medium

Running Clean Login on your site? Check whether your installed version is affected.

Scan your site free

Clean Login <= 1.15 - Unauthenticated Insecure Direct Object Reference

medium

The Clean Login plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.15 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.15
Fixed in:
1.16
Disclosed:
Jun 16, 2026

CVE-2026-54184 on NVD →

Clean Login [clean-login] < 1.14.6

unknown

[en] The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary f...

Affected:
up to 1.14.6
Fixed in:
1.14.6
Disclosed:
Aug 30, 2024

CVE-2024-8252 on NVD →

Clean Login <= 1.14.5 - Authenticated (Contributor+) Local File Inclusion

high

The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files...

CVSS:
8.8
Affected:
up to 1.14.5
Fixed in:
1.14.6
Disclosed:
Aug 29, 2024

CVE-2024-8252 on NVD →

Clean Login [clean-login] < 1.13.7

unknown

[en] The Clean Login WordPress plugin before 1.13.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as adm...

Affected:
up to 1.13.7
Fixed in:
1.13.7
Disclosed:
Feb 6, 2023

CVE-2022-4838 on NVD →

Clean Login <= 1.13.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Clean Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and abo...

CVSS:
6.4
Affected:
up to 1.13.6
Fixed in:
1.13.7
Disclosed:
Jan 10, 2023

CVE-2022-4838 on NVD →

Clean Login 1.12.6.3 - Cross-Site Scripting

medium

The Clean Login for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in version 1.12.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

CVSS:
6.1
Affected:
1.12.6.3 – 1.12.6.3
Fixed in:
1.12.6.4
Disclosed:
Aug 9, 2021

Clean Login [clean-login] < 1.12.6.4

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Clean Login plugin (versions <= 1.12.6.3).

Affected:
up to 1.12.6.4
Fixed in:
1.12.6.4
Disclosed:
Aug 9, 2021

Clean Login [clean-login] < 1.12.6.4

unknown

The Clean Login for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in version 1.12.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

Affected:
up to 1.12.6.4
Fixed in:
1.12.6.4
Disclosed:
Aug 9, 2021

Clean Login <= 1.10.3 - Cross-Site Request Forgery

high

The Clean Login for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.3. This is due to missing or incorrect nonce validation on the clean_login_options() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request grante...

CVSS:
8.8
Affected:
up to 1.10.3
Fixed in:
1.10.4
Disclosed:
Jun 29, 2020

CVE-2017-8875 on NVD →

Clean Login [clean-login] < 1.5.1

unknown

[en] The clean-login plugin before 1.5.1 for WordPress has reflected XSS.

Affected:
up to 1.5.1
Fixed in:
1.5.1
Disclosed:
Aug 22, 2019

CVE-2015-9336 on NVD →

Clean Login [clean-login] < 1.10.4

unknown

[en] CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.

Affected:
up to 1.10.4
Fixed in:
1.10.4
Disclosed:
May 10, 2017

CVE-2017-8875 on NVD →

Clean Login <= 1.5 - Reflected Cross-Site Scripting

medium

The Clean Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on the 'pass' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...

CVSS:
6.1
Affected:
up to 1.5
Fixed in:
1.5.1
Disclosed:
Jul 27, 2015

CVE-2015-9336 on NVD →

Clean Login [clean-login] < 1.12.6.4

unknown

The plugin does not escape the url parameter in its login form page, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 1.12.6.4
Fixed in:
1.12.6.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database