CVE-2026-16295 PUBLISHED

Clearfy < 2.4.3 - Subscriber+ Sensitive Information Disclosure via Factory Page-Action Dispatcher

Assigner: WPScan
Reserved: 20.07.2026 Published: 04.08.2026 Updated: 04.08.2026

The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such as a Subscriber to render admin-only settings pages and disclose their contents, including administrative nonces, while the canonical page URL correctly restricts access.

Product Status

Vendor Unknown
Product Clearfy Cache
Versions Default: unaffected
  • affected from 0 to 2.4.3 (excl.)

Credits

  • Revanth Hari Narayana Matte finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE