Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
clearfy · plugin
Known security vulnerabilities for Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer. Find out in seconds which version runs on your site with WP Lens.
5 known vulnerabilities
3 exploitable without logging in · latest Jan 9, 2026
Listed on wordpress.org · latest 2.4.3 · last updated Jul 23, 2026 · 40K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Medium 5.4
CVE-2024-43260login required≤ 2.2.4
WordPress Clearfy Cache plugin <= 2.2.4 - Broken Access Control vulnerability
- Medium 4.3
CVE-2025-13749unauthenticated · needs a click≤ 2.4.0
Clearfy <= 2.4.0 - Cross-Site Request Forgery to Update Notification Tampering
- Medium 4.3
CVE-2024-13338unauthenticated≤ 2.3.1
Webcraftic Clearfy – WordPress optimization plugin <= 2.3.1 - Cross-Site Request Forgery to Clear Cache
- Medium 4.3
CVE-2024-13337unauthenticated · needs a click≤ 2.3.2
Webcraftic Clearfy – WordPress optimization plugin <= 2.3.2 - Cross-Site Request Forgery to Plugin Settings Update via 'setup-wbcr_clearfy'
- Medium 4.3
CVE-2024-34806login required≤ 2.2.1
WordPress Clearfy Cache plugin <= 2.2.1 - Cross Site Request Forgery (CSRF) vulnerability
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).