Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer < 2.4.3 - Authenticated (Subscriber+) Information Exposure
medium
The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 2.4.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.3
- Disclosed:
- Aug 4, 2026
CVE-2026-16295 on NVD →
Clearfy <= 2.4.2 - Authenticated (Administrator+) PHP Object Injection
medium
The Clearfy plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable so...
- CVSS:
- 6.6
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.3
- Disclosed:
- Jul 24, 2026
CVE-2026-16297 on NVD →
Multiple Plugins <= Multiple Versions - Unauthenticated Stored Cross-Site Scripting
high
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- CVSS:
- 7.2
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.2
- Disclosed:
- Apr 27, 2026
CVE-2026-3220 on NVD →
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer [clearfy] < 2.4.1
unknown
[en] The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.0. This is due to missing nonce validation on the "wbcr_upm_change_flag" function. This makes it possible for unauthenticated at...
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Jan 9, 2026
CVE-2025-13749 on NVD →
Clearfy <= 2.4.0 - Cross-Site Request Forgery to Update Notification Tampering
medium
The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.0. This is due to missing nonce validation on the "wbcr_upm_change_flag" function. This makes it possible for unauthenticated attacke...
- CVSS:
- 4.3
- Affected:
- up to 2.4.0
- Fixed in:
- 2.4.1
- Disclosed:
- Jan 8, 2026
CVE-2025-13749 on NVD →
Clearfy < 2.4.1 - Cross-Site Request Forgery to Update Notification Tampering
medium
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Jan 8, 2026
CVE-2025-13749 on NVD →
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer [clearfy] < 2.3.2 (closed)
unknown
[en] The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on the wclearfy_cache_delete functionality . This makes it possible for...
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Apr 12, 2025
CVE-2024-13338 on NVD →
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer [clearfy] < 2.3.3 (closed)
unknown
[en] The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.2. This is due to missing or incorrect nonce validation on the 'setup-wbcr_clearfy' page. This makes it possible for unauthentic...
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- Apr 12, 2025
CVE-2024-13337 on NVD →
Webcraftic Clearfy – WordPress optimization plugin <= 2.3.1 - Cross-Site Request Forgery to Clear Cache
medium
The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on the wclearfy_cache_delete functionality . This makes it possible for unaut...
- CVSS:
- 5.3
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Apr 11, 2025
CVE-2024-13338 on NVD →
Webcraftic Clearfy – WordPress optimization plugin <= 2.3.2 - Cross-Site Request Forgery to Plugin Settings Update via 'setup-wbcr_clearfy'
medium
The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.2. This is due to missing or incorrect nonce validation on the 'setup-wbcr_clearfy' page. This makes it possible for unauthenticated...
- CVSS:
- 4.3
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- Apr 11, 2025
CVE-2024-13337 on NVD →
Webcraftic Clearfy – WordPress optimization plugin < 2.3.3 - Cross-Site Request Forgery to Plugin Settings Update via 'setup-wbcr_clearfy'
medium
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- Apr 11, 2025
CVE-2024-13337 on NVD →
Webcraftic Clearfy – WordPress optimization plugin < 2.3.2 - Cross-Site Request Forgery to Clear Cache
medium
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Apr 11, 2025
CVE-2024-13338 on NVD →
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer [clearfy] < 2.2.5 (closed)
unknown
[en] Missing Authorization vulnerability in Creative Motion Clearfy Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clearfy Cache: from n/a through 2.2.4.
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Nov 1, 2024
CVE-2024-43260 on NVD →
Clearfy Cache <= 2.2.4 - Missing Authorization
medium
The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber-level access and abov...
- CVSS:
- 4.3
- Affected:
- up to 2.2.4
- Fixed in:
- 2.2.5
- Disclosed:
- Aug 12, 2024
CVE-2024-43260 on NVD →
Clearfy Cache < 2.2.5 - Missing Authorization
medium
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Aug 12, 2024
CVE-2024-43260 on NVD →
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer [clearfy] < 2.3.3 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Clearfy Cache.This issue affects Clearfy Cache: from n/a through 2.2.1.
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- May 17, 2024
CVE-2024-34806 on NVD →
Clearfy Cache <= 2.3.2 - Cross-Site Request Forgery
medium
The Clearfy Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site admini...
- CVSS:
- 4.3
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- May 13, 2024
CVE-2024-34806 on NVD →
Clearfy Cache < 2.3.3 - Cross-Site Request Forgery
medium
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- May 13, 2024
CVE-2024-34806 on NVD →
Clearfy Cache <= 2.0.4 - Reflected Cross-Site Scripting
medium
The Clearfy Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...
- CVSS:
- 6.1
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Jun 14, 2022
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer [clearfy] < 2.0.5 (closed)
unknown
The Clearfy Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Jun 14, 2022
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer [clearfy] < 2.0.5 (closed)
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Clearfy Cache plugin (versions <= 2.0.4).
Update the WordPress Clearfy Cache plugin to the latest available version (at least 2.0.5).
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Jun 14, 2022
Clearfy Cache < 2.0.5 - Reflected Cross-Site Scripting
medium
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Jun 14, 2022
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer [clearfy] < 2.0.5 (closed)
unknown
The plugin does not escape some generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database