WordPress Plugin Vulnerabilities
Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import
Description
The plugin does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
OBJECT INJECTION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Omar Elshopky
Submitter
Omar Elshopky
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-24 (about 11 days ago)
Added
2026-07-24 (about 10 days ago)
Last Updated
2026-07-24 (about 10 days ago)