CVE-2026-16295
4.3 MEDIUMPublished 2026-08-04 · Updated 2026-08-04
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such as a Subscriber to render admin-only settings pages and disclose their contents, including administrative nonces, while the canonical page URL correctly restricts access.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weaknesses
CWE-284
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2025-70962PoC
- MEDIUMCVE-2026-100621PoC
- MEDIUMCVE-2026-100883PoC
- MEDIUMCVE-2026-100906PoC
- MEDIUMCVE-2026-100907PoC
- HIGHCVE-2026-101053PoC
- MEDIUMCVE-2026-101054PoC
- MEDIUMCVE-2026-101055PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.