Impact
The Clearfy Cache WordPress plugin fails to perform a capability check in one of its admin‑page dispatch paths. As a result, any authenticated user, including those with the Subscriber role, is able to render pages that are intended to be accessible only to administrators. This loophole exposes content from the settings pages, including administrative nonces, thereby leaking sensitive configuration data. The vulnerability is a classic unauthorized privilege escalation that ultimately leads to confidentiality compromise rather than code execution or denial of service.
Affected Systems
The issue affects the Clearfy Cache plugin on all WordPress installations where the plugin version is older than 2.4.3. No specific vendor beyond the plugin itself is identified, but the affected installations are any WordPress sites that have installed Clearfy Cache prior to the 2.4.3 release.
Risk and Exploitability
Because the flaw only applies to authenticated users, the attack vector is limited to legitimate subscribers with access to the WordPress backend. The exploit requires no special privileges beyond having an authenticated session, making it relatively easy for a legitimate user to traverse the dispatcher and view the disallowed pages. While the CVSS score is not provided in the public data, the effective risk is moderate: the impact is disclosure of sensitive information and potential facilitation of further attacks through leaked nonces. The vulnerability has not been listed in the CISA KEV catalog, and no EPSS score is available, but the lack of updates to the plugin exacerbates the exposure. The most appropriate remediation is to apply the vendor’s fix.
OpenCVE Enrichment