Unauthenticated Insecure Direct Object References in Clean Login Plugin by WordPress
CVE-2026-54184

8.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2026

What is CVE-2026-54184?

The Clean Login plugin for WordPress versions 1.15 and below is subject to a vulnerability that allows unauthenticated users to access sensitive data through Insecure Direct Object References (IDOR). This can lead to unauthorized access to user accounts or other protected resources, resulting in potential information disclosure and privacy breaches. Implementing security measures and upgrading to patched versions is crucial to mitigate these types of vulnerabilities.

Affected Version(s)

Clean Login <= 1.15

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman | Patchstack Bug Bounty Program
.