What is CVE-2026-16296?
This vulnerability exists in the Clearfy Cache WordPress plugin before version 2.4.3. The Cyrlitera old-URL redirect handler does not validate the redirect target, allowing unauthenticated attackers to redirect users to arbitrary external URLs. The plugin should be immediately updated to the latest version.
Azərbaycanca: Bu zəiflik Clearfy Cache WordPress plaginin 2.4.3-dən əvvəlki versiyalarında mövcuddur. Cyrlitera köhnə URL istiqamətləndirici funksiyasında təsdiqlənməmiş istiqamət parametri səbəbilə autentifikasiya olunmamış hücumçu istifadəçiləri istənilən xarici URL-ə yönləndirə bilər. Plagin dərhal ən son versiyaya yenilənməlidir.
FAQ2
Which component of the Clearfy Cache plugin contains the CVE-2026-16296 vulnerability?
This vulnerability exists in the Cyrlitera old-URL redirect handler of the Clearfy Cache WordPress plugin.
What should users do to protect against CVE-2026-16296?
Users should immediately update the Clearfy Cache plugin to the latest version, which is 2.4.3 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.