CVE-2026-16297: Unknown Clearfy Cache
Medium severity, CVSS 4.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.
Affected products
- Unknown Clearfy Cache: before 2.4.3 (fixed in 2.4.3)
Published 2026-08-03. Last modified 2026-08-26.