/Vulnerability Library

WordPress Clean Login <= 1.14.5 Authenticated (Contributor+) - Local File Inclusion

CVE-2024-8252
Verified

Description

The Clean Login plugin for WordPress up to version 1.14.5 contains a path traversal caused by the 'template' attribute in the clean-login-register shortcode, letting authenticated attackers with contributor access include and execute arbitrary files, exploit requires attacker to have contributor or higher access level.

Severity

High

CVSS Score

8.8

Affected Product

clean-login

Published Date

April 8, 2026

Template Author

pussycat0x

CVE-2024-8252.yaml
8.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE ID:
cwe-98

References

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/clean-login/clean-login-1145-authenticated-contributor-local-file-inclusionhttps://plugins.trac.wordpress.org/changeset/3143241/clean-login

Remediation Steps

Update to the latest version of the plugin, above 1.14.5, to fix the vulnerability.