CyberRota Analysis
AI-GeneratedThe Clearfy Cache plugin for WordPress versions prior to 2.4.3 is vulnerable due to inadequate restrictions on classes during the unserialization of settings-import data. This flaw allows administrators to exploit PHP Object Injection, potentially leading to remote code execution if a suitable gadget chain exists. WordPress site administrators using this plugin should prioritize updating to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.