CVE-2026-19223: Smush < 4.3.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Smush (WordPress plugin)to a version that resolves this vulnerability.Fixed in 4.3.2
Event History
Frequently Asked Questions
Who can exploit this issue?
An administrator of any individual site within a WordPress multisite network can exploit it. The issue allows that site-level administrator to execute arbitrary code across the entire network.
Are standalone WordPress installations affected?
The issue is described as affecting a network-wide setting in WordPress multisite. The provided information does not indicate that standalone, non-multisite WordPress installations are affected.
What versions require remediation?
Smush versions before 4.3.2 are affected. Updating to version 4.3.2 or later removes the described missing restriction on the network-wide setting.