
CVE-2026-16296 The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to an … https://www.cve.org/CVERecord?id=CVE-2026-16296
Post summary
The text announces that Clearfy Cache plugin versions before 2.4.3 contain an unvalidated redirect flaw (CVE-2026-16296); no PoC, exploit, or patch information is provided.


