SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-19223

HIGH · CVSS 7.2 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Smush plugin for WordPress versions prior to 4.3.2 is vulnerable due to insufficient restrictions on network-wide settings, enabling any site administrator within a multisite network to execute arbitrary code across the entire network. This flaw poses a significant risk as it could lead to unauthorized access and control over multiple sites. WordPress multisite administrators and security teams should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-19223
Severity
HIGH
CVSS
7.2
EPSS
0.37%
WordPress

Original NVD Description

The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.