Vulnerabilities and security researches forclearfy clearfy
Direction: ascendingClearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer # 9df440d3c42c1908a8ffe08b2ae2048fa8a6b3b6
- CVE, Research URL
- Home page URL
-
Security reports for Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
- Date
- Jun 14, 2022
- Research Description
- Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer [clearfy] < 2.0.5 WordPress Clearfy Cache plugin <= 2.0.4 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Clearfy Cache plugin (versions <= 2.0.4). Update the WordPress Clearfy Cache plugin to the latest available version (at least 2.0.5).
- Affected versions
-
max 2.0.5.
- Status
-
vulnerable
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer # CVE-2024-34806
- CVE, Research URL
- Home page URL
-
Security reports for Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
- Date
- May 17, 2024
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Clearfy Cache.This issue affects Clearfy Cache: from n/a through 2.2.1.
- Affected versions
-
max 2.3.3.
- Status
-
vulnerable
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer # CVE-2024-43260
- CVE, Research URL
- Home page URL
-
Security reports for Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
- Date
- Nov 01, 2024
- Research Description
- Missing Authorization vulnerability in Creative Motion Clearfy Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clearfy Cache: from n/a through 2.2.4.
- Affected versions
-
max 2.2.5.
- Status
-
vulnerable
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer # CVE-2024-13337
- CVE, Research URL
- Home page URL
-
Security reports for Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
- Date
- Apr 12, 2025
- Research Description
- The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.2. This is due to missing or incorrect nonce validation on the 'setup-wbcr_clearfy' page. This makes it possible for unauthenticated attackers to update the plugins settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 2.3.3.
- Status
-
vulnerable
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer # CVE-2024-13338
- CVE, Research URL
- Home page URL
-
Security reports for Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
- Date
- Apr 12, 2025
- Research Description
- The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on the wclearfy_cache_delete functionality . This makes it possible for unauthenticated attackers to clear the cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 2.3.2.
- Status
-
vulnerable
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer # CVE-2025-13749
- CVE, Research URL
- Home page URL
-
Security reports for Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
- Date
- Jan 09, 2026
- Research Description
- The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.0. This is due to missing nonce validation on the "wbcr_upm_change_flag" function. This makes it possible for unauthenticated attackers to disable plugin/theme update notifications via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 2.4.1.
- Status
-
vulnerable
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer # CVE-2026-3220
- CVE, Research URL
- Home page URL
-
Security reports for Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
- Date
- May 18, 2026
- Research Description
- The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.
- Affected versions
-
max 2.4.2.
- Status
-
vulnerable
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer # a59e7102-13d6-4f1e-b7b1-75eae307e516
- CVE, Research URL
- Home page URL
-
Security reports for Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
- Date
- -
- Research Description
- Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer [clearfy] < 2.0.5 Clearfy Cache < 2.0.5 - Reflected Cross-Site Scripting The plugin does not escape some generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected versions
-
max 2.0.5.
- Status
-
vulnerable
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer # 8f2bd68d9a4800c4aed02d33de2f3a641fc82cd0
- CVE, Research URL
- Home page URL
-
Security reports for Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
- Date
- Jun 14, 2022
- Research Description
- Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer [clearfy] < 2.0.5 Clearfy Cache <= 2.0.4 - Reflected Cross-Site Scripting The Clearfy Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 2.0.5.
- Status
-
vulnerable
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer # CVE-2026-16297
- CVE, Research URL
- Home page URL
-
Security reports for Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
- Date
- Aug 03, 2026
- Research Description
- The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.
- Affected versions
-
max 2.4.3.
- Status
-
vulnerable