CVE-2026-19223
Received Received - Intake

Arbitrary Code Execution in Smush WordPress Plugin

Vulnerability report for CVE-2026-19223, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: WPScan

Description

The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_smush smush to 4.3.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Smush WordPress plugin before version 4.3.2 has a vulnerability where network-wide settings are not restricted to network administrators only. This allows any single site administrator on a multisite network to execute arbitrary code across the entire network.

Detection Guidance

Check the installed version of the Smush plugin in WordPress. If it is below 4.3.2, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files in /wp-content/plugins/smush/

Impact Analysis

If you are an administrator on a multisite WordPress network using Smush before 4.3.2, an attacker with access to any single site could take over the entire network by executing malicious code. This could lead to data breaches, unauthorized access, or complete system compromise.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations could face legal penalties, fines, or reputational damage if exploited.

Mitigation Strategies

Update the Smush plugin to version 4.3.2 or later immediately. Restrict network administrator privileges to trusted users only. Monitor for unusual activity across the multisite network.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19223. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart