WordPress Plugin Vulnerabilities

Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import

Description

The plugin does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.

Proof of Concept

Affects Plugins

Fixed in 2.4.3

References

Classification

Type
OBJECT INJECTION
CWE

Miscellaneous

Original Researcher
Omar Elshopky
Submitter
Omar Elshopky
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-07-24 (about 11 days ago)
Added
2026-07-24 (about 10 days ago)
Last Updated
2026-07-24 (about 10 days ago)

Other