CyberRota Analysis
AI-GeneratedThe Clearfy Cache plugin for WordPress prior to version 2.4.3 is vulnerable due to a lack of capability checks, allowing any authenticated user, including those with minimal permissions like Subscribers, to access and view sensitive admin-only settings pages. This exposure could lead to the disclosure of critical information, such as administrative nonces, potentially enabling further attacks. WordPress site administrators and security teams should prioritize updating this plugin to mitigate the risk of unauthorized access to sensitive configurations.
Original NVD Description
The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such as a Subscriber to render admin-only settings pages and disclose their contents, including administrative nonces, while the canonical page URL correctly restricts access.