---
id: CVE-2026-90976
title: >-
  The Clean Login WordPress plugin before 1.19 does not check whether user
  registration is enabled before creating an account in its registration
  handler, allowing unauthenticated users to create accounts even when the site
  has registratio…
summary: >-
  The Clean Login WordPress plugin before 1.19 does not check whether user
  registration is enabled before creating an account in its registration
  handler, allowing unauthenticated users to create accounts even when the site
  has registratio…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-284
product: Clean Login
affected:
  - clean_login < 1.19
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90976'
references:
  - url: 'https://wpscan.com/vulnerability/e72f9529-6500-4ed2-a8cc-d77045b6be5c/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00304
epssPercentile: 0.20609
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-18T10:55:52.807611Z'
ingestedAt: '2026-09-18T06:36:37.990Z'
---

## Overview

The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an account in its registration handler, allowing unauthenticated users to create accounts even when the site has registration disabled.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
