Executive brief
Smush is a popular WordPress plugin for image optimization and compression. An unauthenticated attacker can trigger a denial of service condition, causing the affected website to become slow or go offline. This vulnerability affects versions 4.2.0 and earlier.
Technical details
The vulnerability is a denial of service flaw in Smush Image Compression and Optimization plugin versions 4.2.0 and earlier, classified as insecure design (OWASP A4). It requires no authentication and can be exploited over the network to overwhelm server resources. An attacker can trigger resource-intensive operations that degrade site performance or cause a complete outage. The vulnerability is fixed in version 4.3.0 and later.
Affected products
- WPMU DEV Smush Image Compression and Optimization <=4.2.0
Timeline
- 2026-08-28: disclosed: Public disclosure via NVD
- 2026: patched: Fixed in version 4.3.0
- 2026-07-14: other: Vulnerability reported to vendor