CVE-2026-16296EPSS p19.7%
CVE-2026-16296CVE-2026-16296
Description
The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to an unsafe redirect function, which allows unauthenticated attackers to redirect visitors to an arbitrary external URL when a non-default option is enabled.
Scoring
| CVSS | 4.7 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N |
| EPSS | 0.29% probability of exploitation · percentile 19.7% · 2026-10-06T12:00:23Z |
| Last modified | 2026-08-26 |