CVE-2024-13337: Webcraftic Clearfy – WordPress optimization plugin <= 2.3.2 - Cross-Site Request Forgery to Plugin Settings Update via 'setup-wbcr_clearfy'
The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.2. This is due to missing or incorrect nonce validation on the 'setup-wbcrclearfy' page. This makes it possible for unauthenticated attackers to update the plugins settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13337?
CVE-2024-13337 has a high severity level due to the potential for Cross-Site Request Forgery attacks.
How do I fix CVE-2024-13337?
To fix CVE-2024-13337, update the Clearfy plugin to version 2.3.3 or higher where nonce validation has been properly implemented.
Who is affected by CVE-2024-13337?
Any WordPress site using the Clearfy optimization plugin version 2.3.2 or earlier is affected by CVE-2024-13337.
What type of vulnerability is CVE-2024-13337?
CVE-2024-13337 is a Cross-Site Request Forgery vulnerability that can allow unauthorized actions on behalf of a user.
What are the implications of CVE-2024-13337?
If exploited, CVE-2024-13337 could lead to unauthorized changes being made to the plugin settings without the user's consent.