Description
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
Published: 2026-08-27
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution across multisite networks
Action: Immediate Patch
AI Analysis

Impact

The Smush plugin before version 4.3.2 does not restrict a network‑wide setting to network administrators, which allows a site administrator on a multisite WordPress network to trigger arbitrary code execution across every site. This flaw gives the attacker full control over the web hosting environment, enabling modification of site content or execution of commands, and constitutes a classic remote code execution vulnerability.

Affected Systems

Smush WordPress plugin versions earlier than 4.3.2 installed on a WordPress multisite network. Any user with site‑administrator privileges can exploit the unchecked setting to affect all sites in the network.

Risk and Exploitability

The vulnerability has a CVSS score of 7.2, indicating high‑severity remote code execution risk. Because the EPSS score is <1% and the flaw is not listed in the CISA KEV catalog, the likelihood of exploitation remains low but uncertain, while the potential for widespread compromise is severe. An attacker who can act as a site administrator can use the unchecked network‑wide option to run arbitrary code across the entire network, potentially leading to widespread compromise.

Generated by OpenCVE AI on August 27, 2026 at 18:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Smush plugin to version 4.3.2 or later.
  • If an upgrade is not immediately possible, disable or remove the hub connector network‑wide setting and ensure that only network super‑admins can modify network‑wide options.
  • Apply strict role‑based access controls so that ordinary site administrators cannot alter network‑wide settings.
  • Consider using additional security plugins to monitor privileged actions and detect unauthorized changes.

Generated by OpenCVE AI on August 27, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 27 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 27 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
Title Smush < 4.3.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-27T14:23:47.838Z

Reserved: 2026-08-07T09:04:31.670Z

Link: CVE-2026-19223

cve-icon Vulnrichment

Updated: 2026-08-27T14:15:23.695Z

cve-icon NVD

Status : Deferred

Published: 2026-08-27T06:16:56.803

Modified: 2026-08-28T18:43:25.883

Link: CVE-2026-19223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T19:00:07Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')