WordPress Clean Login <= 1.14.5 Authenticated (Contributor+) - Local File Inclusion
CVE-2024-8252
Verified
Description
The Clean Login plugin for WordPress up to version 1.14.5 contains a path traversal caused by the 'template' attribute in the clean-login-register shortcode, letting authenticated attackers with contributor access include and execute arbitrary files, exploit requires attacker to have contributor or higher access level.
Severity
High
CVSS Score
8.8
Affected Product
clean-login
Published Date
April 8, 2026
Template Author
pussycat0x
CVE-2024-8252.yaml
8.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE ID:
cwe-98
Remediation Steps
Update to the latest version of the plugin, above 1.14.5, to fix the vulnerability.