Feed/CVE-2026-16296
CVE-2026-16296MEDIUMCVSS 4.7

CVE-2026-16296

Published Aug 4, 2026·Updated Aug 4, 2026

NVD Description

The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to an unsafe redirect function, which allows unauthenticated attackers to redirect visitors to an arbitrary external URL when a non-default option is enabled.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free