Vulnerabilities and security researches forclean-login clean-login
Direction: ascendingJun 06, 2024
Clean Login # CVE-2022-4838
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 07, 2023
- Research Description
- The Clean Login WordPress plugin before 1.13.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
- Affected versions
-
max 1.13.7.
- Status
-
vulnerable
Clean Login # CVE-2015-9336
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 22, 2019
- Research Description
- The clean-login plugin before 1.5.1 for WordPress has reflected XSS.
- Affected versions
-
max 1.5.1.
- Status
-
vulnerable
Clean Login # CVE-2017-8875
- CVE, Research URL
- Home page URL
- Application
- Date
- May 10, 2017
- Research Description
- CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.
- Affected versions
-
max 1.10.4.
- Status
-
vulnerable
Aug 31, 2024
Clean Login # CVE-2024-8252
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 30, 2024
- Research Description
- The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
- Affected versions
-
max 1.14.6.
- Status
-
vulnerable
Jun 16, 2026
Clean Login # bb61c8c631c4e3f230fa416217fad1faed0bc7cc
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 09, 2021
- Research Description
- Clean Login [clean-login] < 1.12.6.4 Clean Login 1.12.6.3 - Cross-Site Scripting The Clean Login for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in version 1.12.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 1.12.6.4.
- Status
-
vulnerable
Clean Login # 3d9eaa892a375918308e2fa1270214d16eb5d844
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 09, 2021
- Research Description
- Clean Login [clean-login] < 1.12.6.4 WordPress Clean Login plugin <= 1.12.6.3 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Clean Login plugin (versions <= 1.12.6.3).
- Affected versions
-
max 1.12.6.4.
- Status
-
vulnerable
Clean Login # 6782ee79-6930-4a40-b416-d2248f78d995
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Clean Login [clean-login] < 1.12.6.4 Clean Login 1.12.6.3 - Reflected Cross-Site Scripting The plugin does not escape the url parameter in its login form page, leading to a Reflected Cross-Site Scripting issue
- Affected versions
-
max 1.12.6.4.
- Status
-
vulnerable
Jun 19, 2026
Clean Login # CVE-2026-54184
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 17, 2026
- Research Description
- Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
- Affected versions
-
max 1.16.
- Status
-
vulnerable