Vulnerabilities > Codection > Clean Login > High

DATE CVE VULNERABILITY TITLE RISK
2024-08-30 CVE-2024-8252 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Codection Clean Login
The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode.
network
low complexity
codection CWE-829
8.8