S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Apr 9, 2026

CVE-2024-8252 Scanner

CVE-2024-8252 Scanner - Local File Inclusion vulnerability in WordPress Clean Login Plugin

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-8252
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Clean Loginby hornero
0
clean_loginby codection
0
Updated Aug 22, 2026View on NVD →
Detail

The WordPress Clean Login plugin is widely used by website administrators who wish to provide a user-friendly login interface on their WordPress sites. Developed by Codection, Clean Login offers features such as login, registration, and password recovery integrated into the WordPress environment. This plugin is particularly popular among bloggers, small business websites, and online communities. Its functionality and ease of use make it a sought-after addition to customize login pages. However, like any plugin, it requires regular updates to maintain security. It is used by people looking for simple deployment without additional technical overhead.

Local File Inclusion (LFI) is a vulnerability that allows an attacker to include files, usually remotely, that are primarily accessible via the web server. The Clean Login plugin up to version 1.14.5 is susceptible to LFI due to improper sanitization of input associated with template file inclusion. Exploiting this vulnerability, attackers with authenticated access can navigate to restricted local files. Such vulnerabilities can lead to significant security risks including exposure of sensitive files and execution of arbitrary code if not addressed promptly. It is crucial for systems using vulnerable versions of the plugin to mitigate risks associated with LFI.

The vulnerability resides in the 'template' attribute of the 'clean-login-register' shortcode within the Clean Login plugin. Authenticated users, specifically those with contributor access or higher, use this endpoint to include unintended files. The 'template' attribute does not adequately filter or escape path traversal sequences, enabling the LFI attack vector. Attackers can craft requests that point to critical system files, potentially leading to unauthorized code execution. Regular expressions and status checks in HTTP response are typically used in scans to confirm the presence of this vulnerability. Timely detection and remediation are crucial to prevent exploitation.

Exploitation of the Local File Inclusion vulnerability in the Clean Login plugin could lead to severe consequences. Malicious exploits may gain unauthorized access to sensitive user data, manipulate or destroy files, and in worst-case scenarios, obtain control over the web server hosting the vulnerable WordPress site. This can lead to site defacement, data theft, or the planting of backdoors for persistent access. Furthermore, compromised files and injected code can damage the server's integrity, disrupt services, and potentially spread across the network affecting other connected devices. Mitigating such risks entails prompt patching and enhancing access controls.

REFERENCES

Solution Advice
  • Upgrade to a version of the Clean Login plugin beyond 1.14.5 to remove the vulnerability.
  • Apply least privilege access controls, limiting permissions to necessary operations only.
  • Regularly audit plugins and extensions for updates or known vulnerabilities.
  • Implement a Web Application Firewall (WAF) to help block exploits targeting LFI vulnerabilities.
  • Conduct security training for administrators to identify potential security threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.