Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-whxq-7ph8-rv4q

Опубликовано: 18 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.

The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.

EPSS

Процентиль: 20%
0.00272
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-697

Связанные уязвимости

CVSS3: 5.3
nvd
2 дня назад

The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.

EPSS

Процентиль: 20%
0.00272
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-697