cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forclean-login clean-login

Direction: ascending
Jun 06, 2024

Clean Login # CVE-2022-4838

CVE, Research URL

CVE-2022-4838

Application

Clean Login

Date
Feb 07, 2023
Research Description
The Clean Login WordPress plugin before 1.13.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected versions
max 1.13.7.
Status
vulnerable

Clean Login # CVE-2015-9336

CVE, Research URL

CVE-2015-9336

Application

Clean Login

Date
Aug 22, 2019
Research Description
The clean-login plugin before 1.5.1 for WordPress has reflected XSS.
Affected versions
max 1.5.1.
Status
vulnerable

Clean Login # CVE-2017-8875

CVE, Research URL

CVE-2017-8875

Application

Clean Login

Date
May 10, 2017
Research Description
CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.
Affected versions
max 1.10.4.
Status
vulnerable
Aug 31, 2024

Clean Login # CVE-2024-8252

CVE, Research URL

CVE-2024-8252

Application

Clean Login

Date
Aug 30, 2024
Research Description
The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Affected versions
max 1.14.6.
Status
vulnerable
Jun 16, 2026

Clean Login # bb61c8c631c4e3f230fa416217fad1faed0bc7cc

Application

Clean Login

Date
Aug 09, 2021
Research Description
Clean Login [clean-login] < 1.12.6.4 Clean Login 1.12.6.3 - Cross-Site Scripting The Clean Login for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in version 1.12.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.12.6.4.
Status
vulnerable

Clean Login # 3d9eaa892a375918308e2fa1270214d16eb5d844

Application

Clean Login

Date
Aug 09, 2021
Research Description
Clean Login [clean-login] < 1.12.6.4 WordPress Clean Login plugin <= 1.12.6.3 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Clean Login plugin (versions <= 1.12.6.3).
Affected versions
max 1.12.6.4.
Status
vulnerable

Clean Login # 6782ee79-6930-4a40-b416-d2248f78d995

Application

Clean Login

Date
-
Research Description
Clean Login [clean-login] < 1.12.6.4 Clean Login 1.12.6.3 - Reflected Cross-Site Scripting The plugin does not escape the url parameter in its login form page, leading to a Reflected Cross-Site Scripting issue
Affected versions
max 1.12.6.4.
Status
vulnerable
Jun 19, 2026

Clean Login # CVE-2026-54184

CVE, Research URL

CVE-2026-54184

Application

Clean Login

Date
Jun 17, 2026
Research Description
Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
Affected versions
max 1.16.
Status
vulnerable