GHSA-fwv9-6885-g85cHighCVSS 7.2

The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network...

Published
August 27, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (1)

📋 Description

The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

🔗 References (3)