Description
The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such as a Subscriber to render admin-only settings pages and disclose their contents, including administrative nonces, while the canonical page URL correctly restricts access.
Published: 2026-08-04
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Clearfy Cache WordPress plugin fails to perform a capability check in one of its admin-page dispatch paths. As a result, any authenticated user, even those with the Subscriber role, can render pages that are intended to be accessible only to administrators. This flaw lets the attacker view the contents of administrative settings pages, exposing sensitive configuration data such as administrative nonces. The weakness is a classic unauthorized privilege escalation and corresponds to CWE‑284, exposing higher-privilege data to lower-privilege users.

Affected Systems

The issue affects all WordPress installations running Clearfy Cache prior to version 2.4.3. Any site that has installed the plugin before the 2.4.3 release is vulnerable; no other vendors or product lines are involved.

Risk and Exploitability

Because the vulnerability only applies to authenticated users, the attack vector is limited to legitimate subscribers logged into the WordPress backend. No special privileges are required beyond an existing session, making exploitation straightforward. The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of < 1 % suggests a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Overall, the risk is primarily the disclosure of sensitive configuration information, which could aid further attacks if administrative nonces are leaked.

Generated by OpenCVE AI on August 4, 2026 at 23:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Clearfy Cache plugin to version 2.4.3 or later to apply the vendor’s fix for the missing capability check.
  • If an immediate update is not possible, remove Subscriber role access to the plugin’s settings pages by modifying role capabilities or using a security plugin to block plugin-specific admin pages.
  • Continuously monitor WordPress audit logs for unexpected access or requests to the dispatcher parameters and verify that role checks correctly enforce authorization.

Generated by OpenCVE AI on August 4, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 04 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Tue, 04 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Clearfy Cache
Clearfy Cache clearfy Cache
Wordpress
Wordpress wordpress
Vendors & Products Clearfy Cache
Clearfy Cache clearfy Cache
Wordpress
Wordpress wordpress

Tue, 04 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such as a Subscriber to render admin-only settings pages and disclose their contents, including administrative nonces, while the canonical page URL correctly restricts access.
Title Clearfy < 2.4.3 - Subscriber+ Sensitive Information Disclosure via Factory Page-Action Dispatcher
References

Subscriptions

Clearfy Cache Clearfy Cache
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-04T14:16:50.633Z

Reserved: 2026-07-20T12:29:56.541Z

Link: CVE-2026-16295

cve-icon Vulnrichment

Updated: 2026-08-04T14:16:22.185Z

cve-icon NVD

Status : Received

Published: 2026-08-04T07:16:30.043

Modified: 2026-08-04T15:16:27.220

Link: CVE-2026-16295

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:30:15Z

Weaknesses