Unauthenticated Insecure Direct Object References in Clean Login Plugin by WordPress
CVE-2026-54184
8.2HIGH
What is CVE-2026-54184?
The Clean Login plugin for WordPress versions 1.15 and below is subject to a vulnerability that allows unauthenticated users to access sensitive data through Insecure Direct Object References (IDOR). This can lead to unauthorized access to user accounts or other protected resources, resulting in potential information disclosure and privacy breaches. Implementing security measures and upgrading to patched versions is crucial to mitigate these types of vulnerabilities.
Affected Version(s)
Clean Login <= 1.15