CVE-2024-13338: Webcraftic Clearfy – WordPress optimization plugin <= 2.3.1 - Cross-Site Request Forgery to Clear Cache
The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on the wclearfycachedelete functionality . This makes it possible for unauthenticated attackers to clear the cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13338?
CVE-2024-13338 has a medium severity rating due to the potential for Cross-Site Request Forgery exploits.
How do I fix CVE-2024-13338?
To fix CVE-2024-13338, update the Clearfy Cache plugin to version 2.3.2 or later, which addresses the nonce validation issue.
Which versions of the Clearfy Cache plugin are affected by CVE-2024-13338?
CVE-2024-13338 affects all versions of the Clearfy Cache plugin up to and including version 2.3.1.
What type of vulnerability is CVE-2024-13338?
CVE-2024-13338 is a Cross-Site Request Forgery vulnerability that can allow unauthorized actions on behalf of users.
Can I mitigate CVE-2024-13338 without updating?
It is not recommended to mitigate CVE-2024-13338 without updating, as proper nonce validation is essential for security.