CVE-2026-81285
Deferred Deferred - Pending Action

Unauthenticated Denial of Service in Smush Image Compression

Vulnerability report for CVE-2026-81285, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: Patchstack

Description

Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-08-29
AI Q&A
2026-08-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_smushit smush_image_compression_and_optimization to 4.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-81285 is an unauthenticated Denial of Service (DoS) vulnerability in the Smush Image Compression and Optimization WordPress plugin versions 4.2.0 and below. Attackers can exploit this flaw to crash websites or make them unresponsive without needing authentication.

Detection Guidance

To detect this vulnerability, check the installed version of the Smush Image Compression and Optimization plugin. If the version is 4.2.0 or below, the system is vulnerable. Use the WordPress admin panel or run a command like 'wp plugin list' in the WordPress directory to verify the plugin version.

Impact Analysis

This vulnerability can cause your website to become unavailable, affecting user access and potentially disrupting services. It may impact thousands of sites regardless of traffic or popularity, leading to downtime and loss of functionality.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by causing service disruptions or downtime, potentially leading to unauthorized access or data processing interruptions. A DoS attack may violate availability requirements under these regulations, especially if it affects systems handling sensitive personal or health data.

Mitigation Strategies

Immediately update the Smush plugin to version 4.3.0 or later. If updating is not possible, contact your hosting provider or web developer for assistance. Enable auto-updates for vulnerable plugins if using Patchstack.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81285. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart