๐Ÿ” CVE Alert

CVE-2026-16297

UNKNOWN 0.0

Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.

Vendor unknown
Product clearfy cache
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for unknown clearfy cache

Be the first to know when new unknown vulnerabilities affecting unknown clearfy cache are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Clearfy Cache
0 < 2.4.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/3daf62cd-eefe-49ec-89f7-b13f88111853/

Credits

Omar Elshopky WPScan