PT-2026-67109 · WordPress · Clearfy Cache
CVSS v3.1
4.1
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Clearfy Cache WordPress plugin versions prior to 2.4.3
Description
Users with administrator access can perform PHP Object Injection attacks because the plugin does not restrict the classes allowed when unserializing settings-import data. This may lead to remote code execution if a suitable gadget chain is present in the environment. PHP Object Injection is a vulnerability that occurs when untrusted input is passed to the
unserialize() function, allowing an attacker to manipulate the object's properties or trigger unexpected code execution.Recommendations
Update the plugin to version 2.4.3 or later.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearfy Cache