Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer, CVE-2026-16297
- CVE, Research URL
- Home page URL
-
Security reports for Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
- Published on
- Aug 03, 2026
- Research Description
- The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.
- Affected versions
-
max 2.4.3.
- Status
-
vulnerable