Impact
The Clearfy Cache WordPress plugin fails to perform a capability check in one of its admin-page dispatch paths. As a result, any authenticated user, even those with the Subscriber role, can render pages that are intended to be accessible only to administrators. This flaw lets the attacker view the contents of administrative settings pages, exposing sensitive configuration data such as administrative nonces. The weakness is a classic unauthorized privilege escalation and corresponds to CWE‑284, exposing higher-privilege data to lower-privilege users.
Affected Systems
The issue affects all WordPress installations running Clearfy Cache prior to version 2.4.3. Any site that has installed the plugin before the 2.4.3 release is vulnerable; no other vendors or product lines are involved.
Risk and Exploitability
Because the vulnerability only applies to authenticated users, the attack vector is limited to legitimate subscribers logged into the WordPress backend. No special privileges are required beyond an existing session, making exploitation straightforward. The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of < 1 % suggests a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Overall, the risk is primarily the disclosure of sensitive configuration information, which could aid further attacks if administrative nonces are leaked.
OpenCVE Enrichment