What is CVE-2026-16297?
The Clearfy Cache WordPress plugin before version 2.4.3 fails to restrict allowed classes during the unserialization of settings-import data, enabling administrators to perform PHP Object Injection attacks. This could lead to remote code execution if a suitable gadget chain is present in the environment. Affected sites should immediately update to version 2.4.3 or later.
Azərbaycanca: Clearfy Cache WordPress plugin-in 2.4.3-dən əvvəlki versiyalarında administrator səlahiyyətli istifadəçilərə settings-import məlumatlarını unserialize edərkən icazə verilən siniflərin məhdudlaşdırılmaması səbəbindən PHP Object Injection hücumları həyata keçirməyə imkan verən boşluq aşkarlanıb; bu, mühitdə uyğun gadget chain mövcud olduqda uzaqdan kod icrasına (RCE) yol aça bilər. Təsirə məruz qalan saytlar dərhal plugin-i 2.4.3 versiyasına və ya daha yuxarısına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which user role is affected by the CVE-2026-16297 vulnerability in the Clearfy Cache plugin?
The vulnerability affects users with administrator privileges, as they can perform PHP Object Injection attacks during the unserialization of settings-import data.
To which version should Clearfy Cache be updated to protect against CVE-2026-16297?
The Clearfy Cache plugin should be updated to version 2.4.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.