← WordPress Vulnerabilities
WordPress security by component

Clearfy Cache

Clearfy Cache (clearfy-cache) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 4.7.

Plugin slug: clearfy-cache

CVE-2026-16296: Clearfy Cyrlitera redirects accept arbitrary external destinations

Clearfy Cache before 2.4.3 decodes the request URI in its Cyrlitera old-URL redirect handler and passes the result to an unsafe redirect function without validating the destination. When the non-default old-URL redirect option is enabled, an unauthenticated attacker can construct a site URL that redirects visitors to an arbitrary external location. The public advisory does not disclose the handler, option name, URI encoding or redirect function.

PublishedAug 04, 2026
Known safe version2.4.3
Published vulnerabilities for clearfy-cache
Safe version
Aug 04, 2026 CVE-2026-16296
Clearfy Cyrlitera redirects accept arbitrary external destinations
Clearfy Cache before 2.4.3 decodes the request URI in its Cyrlitera old-URL redirect handler and passes the result to an unsafe redirect function without validating the destination. When the non-default old-URL redirect option is enabled, an unauthenticated attacker can construct a site URL that redirects visitors to an arbitrary external location. The public advisory does not disclose the handler, option name, URI encoding or redirect function.
2.4.3
CVE4.7
NVDPending
Aug 04, 2026 CVE-2026-16295
Clearfy admin dispatch exposes settings pages and nonces to Subscribers
Clearfy Cache before 2.4.3 omits a capability check from an alternate admin-page dispatch path. Any authenticated user, including a Subscriber, can use that path to render settings pages that the canonical page URL correctly restricts, disclosing administrative settings and nonces. The public advisory does not disclose the dispatch route, page parameter, callback, exposed nonce actions or whether a disclosed nonce enables a separate privileged operation.
2.4.3
CVE4.3
NVDPending
Aug 03, 2026 CVE-2026-16297
Clearfy Cache settings imports permit PHP object injection
Clearfy Cache before 2.4.3 unserializes settings-import data without restricting permitted PHP classes. An Administrator can supply a crafted serialized object; if the WordPress environment contains a compatible gadget chain, object destruction or wakeup behavior may lead to remote code execution. The CNA record does not disclose the import route, field, unserialize call or a confirmed gadget chain.
2.4.3
CVE4.1
NVDPending