The Clean Login plugin for WordPress up to version 1.14.5 contains a path traversal caused by the 'template' attribute in the clean-login-register shortcode, letting authenticated attackers with contributor access include and execute arbitrary files, exploit requires attacker to have contributor or higher access level.
id: CVE-2024-8252
info:
name: WordPress Clean Login <= 1.14.5 Authenticated (Contributor+) - Loca
...