What is CVE-2026-16295?
CVE-2026-16295 affects the "Clearfy Cache" WordPress plugin versions prior to 2.4.3. It allows any authenticated user, such as a Subscriber, to access admin-only settings pages and disclose their contents, including administrative nonces, due to a missing capability check. Update the plugin to the latest version.
Azərbaycanca: CVE-2026-16295 "Clearfy Cache" WordPress plaginin 2.4.3-dən əvvəlki versiyalarını təsir edir. Autentifikasiya olunmuş istənilən istifadəçi (məsələn, Subscriber) admin səhifələrinə daxil olub həssas idarəetmə parametrlərini və admin nonce-ləri görə bilər. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the “Clearfy Cache” plugin are affected by CVE-2026-16295?
The vulnerability affects versions of the “Clearfy Cache” WordPress plugin prior to 2.4.3.
What level of authenticated user can exploit CVE-2026-16295?
Any authenticated user, such as a Subscriber, can exploit the vulnerability to view sensitive information on admin pages.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.