Impact
The vulnerability allows an unauthenticated attacker to trigger a denial of service by repeatedly invoking image compression requests through the Smush Image Compression and Optimization plugin. This results in the target WordPress site consuming excess CPU and memory resources, potentially causing slowdowns or a complete unavailability of the web application. The weakness is classified as resource exhaustion (CWE-770).
Affected Systems
The flaw affects the Smush Image Compression and Optimization plugin from WPMU DEV with any version up to and including 4.2.0. Users who have not upgraded beyond 4.2.0 are at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity of the impact. While an EPSS score is not available, the fact that the attack is unauthenticated implies that any user, even without credentials, could trigger the DoS. The vulnerability is not listed in the CISA KEV catalog, suggesting that no public exploits have been reported yet, but the high severity and ease of exploitation warrant prompt attention.
OpenCVE Enrichment