Impact
The Smush plugin before version 4.3.2 does not restrict a network‑wide setting to network administrators, which allows a site administrator on a multisite WordPress network to trigger arbitrary code execution across every site. This flaw gives the attacker full control over the web hosting environment, enabling modification of site content or execution of commands, and constitutes a classic remote code execution vulnerability.
Affected Systems
Smush WordPress plugin versions earlier than 4.3.2 installed on a WordPress multisite network. Any user with site‑administrator privileges can exploit the unchecked setting to affect all sites in the network.
Risk and Exploitability
The vulnerability has a CVSS score of 7.2, indicating high‑severity remote code execution risk. Because the EPSS score is <1% and the flaw is not listed in the CISA KEV catalog, the likelihood of exploitation remains low but uncertain, while the potential for widespread compromise is severe. An attacker who can act as a site administrator can use the unchecked network‑wide option to run arbitrary code across the entire network, potentially leading to widespread compromise.
OpenCVE Enrichment