WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Clean Login

Custom frontend login, registration, user profile and password reset forms via shortcodes — no coding required. WPML certified, reCAPTCHA and WooComme …

6Reported vulnerabilities
8.8Highest CVSS score
1.18Latest version
6,000+Active installs

What to do now

Update Clean Login to 1.16 or later. 6 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 5, 2026 / Tested up to WordPress: 6.9.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2017-8875 Medium 6.5 0.6% 1.7.12 to 1.7.12 (inclusive) 1.10.4 May 10, 2017
CVE-2024-8252 High 8.8 3.0% Before 1.14.6 1.14.6 August 30, 2024
CVE-2022-4838 Medium 5.4 0.6% Before 1.13.7 1.13.7 February 6, 2023
CVE-2015-9336 Medium 6.1 0.9% Before 1.5.1 1.5.1 August 22, 2019
WF-1a91e973-f669-49a6-8c74-f6fbc4dc8db9 Medium 6.1 1.12.6.3 to 1.12.6.3 (inclusive) 1.12.6.4 August 9, 2021
CVE-2026-54184 Medium 5.3 0.3% 1.15 and earlier 1.16 June 16, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.