CyberRota Analysis
AI-GeneratedThe Smush plugin for WordPress versions prior to 4.3.2 is vulnerable due to insufficient restrictions on network-wide settings, enabling any site administrator within a multisite network to execute arbitrary code across the entire network. This flaw poses a significant risk as it could lead to unauthorized access and control over multiple sites. WordPress multisite administrators and security teams should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.