PT-2026-67660 · WordPress · Clearfy Cache

CVE-2026-16295

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Clearfy Cache WordPress plugin versions prior to 2.4.3
Description An issue exists where the plugin fails to perform a capability check in one of its admin-page dispatch paths. This allows any authenticated user, including those with Subscriber level permissions, to render settings pages intended only for administrators. Consequently, sensitive information, such as administrative nonces (unique tokens used to prevent cross-site request forgery), can be disclosed, even though the canonical page URL maintains the correct access restrictions.
Recommendations Update the plugin to version 2.4.3 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16295

Affected Products

Clearfy Cache