Smush

WordPress plugin · smush · WordPress.org ↗
0
Critical
1
High
1
Known total
0
Unfixed
Running Smush on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 7.2
Smush < 4.3.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite
CVE.org
>=3.22.1, <4.3.2 v4.3.2 CVE-2026-19223 Aug 27, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.