CVE-2026-19223 PUBLISHED

Smush < 4.3.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite

Assigner: WPScan
Reserved: 07.08.2026 Published: 27.08.2026 Updated: 27.08.2026

The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

Product Status

Vendor Unknown
Product Smush
Versions Default: unaffected
  • affected from 3.22.1 to 4.3.2 (excl.)

Credits

  • Jakub Herman finder
  • WPScan coordinator

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE