Impact
The Clearfy Cache WordPress plugin before version 2.4.3 allows unauthenticated attackers to supply a redirect target that is not validated by the plugin. The Cyrlitera old‑URL redirect handler decodes the request URI and passes it to an insecure redirect function, enabling a redirect to any external site. This flaw is a classic URL Redirection to Untrusted Resource (CWE‑601) and can be exploited to trick visitors into phishing sites, drive‑by downloads, or other malicious actions, compromising user trust and potentially leading to credential theft or malware delivery.
Affected Systems
All WordPress installations running the Clearfy Cache plugin with a version older than 2.4.3, when a non‑default option is enabled that activates the Cyrlitera redirect logic. The vulnerability exists regardless of user role and requires only that the attacker can direct a victim to a URL that triggers the redirect handler.
Risk and Exploitability
The vulnerability has no publicly reported exploitation data and is not listed in the CISA KEV catalog. Because the exploit requires no authentication and can be achieved through a standard HTTP request, the risk is considered moderate to high for environments where the affected plugin is enabled. The lack of an EPSS score or KEV listing suggests low current exploitation probability, but the potential impact of phishing or social‑engineering attacks warrants proactive remediation.
OpenCVE Enrichment