PT-2026-67660 · WordPress · Clearfy Cache
CVE-2026-16295
·
Published
2026-08-04
·
Updated
2026-08-04
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Clearfy Cache WordPress plugin versions prior to 2.4.3
Description
An issue exists where the plugin fails to perform a capability check in one of its admin-page dispatch paths. This allows any authenticated user, including those with Subscriber level permissions, to render settings pages intended only for administrators. Consequently, sensitive information, such as administrative nonces (unique tokens used to prevent cross-site request forgery), can be disclosed, even though the canonical page URL maintains the correct access restrictions.
Recommendations
Update the plugin to version 2.4.3 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearfy Cache