AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-16296

UNKNOWN · CVSS N/A EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The Clearfy Cache plugin for WordPress versions prior to 2.4.3 is vulnerable due to improper validation of redirect targets, allowing unauthenticated attackers to exploit this flaw and redirect users to arbitrary external URLs. This could lead to phishing attacks or other malicious activities targeting site visitors. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2026-16296
Severity
UNKNOWN
CVSS
N/A
EPSS
0.14%
WordPress

Original NVD Description

The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to an unsafe redirect function, which allows unauthenticated attackers to redirect visitors to an arbitrary external URL when a non-default option is enabled.