WordPress · Clean Login · CVE-2026-90977
**Name of the Vulnerable Software and Affected Versions**
Clean Login WordPress plugin versions prior to 1.19
**Description**
The plugin fails to verify the registration CAPTCHA when the stored session value is empty. This allows unauthenticated users to bypass anti-automation controls on the registration form and create accounts without solving the CAPTCHA.
**Recommendations**
Update the Clean Login WordPress plugin to version 1.19 or later.