ZeroHour

CVE-2026-81285

mass

Unauthenticated DoS in Smush Image Compression and Optimization WordPress Plugin

CVSS 3.1
7.5 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-81285 is an unauthenticated denial-of-service vulnerability (CWE-770, allocation of resources without limits or throttling) in the Smush Image Compression and Optimization WordPress plugin, affecting all versions up to and including 4.2.0. Because the issue is reachable over the network without authentication or user interaction (per the CVSS vector AV:N/AC:L/PR:N/UI:N), a remote attacker can repeatedly trigger resource allocation without limits. The impact is availability only: a successful attack can exhaust server resources and leave the affected WordPress site slow or unresponsive, with no confidentiality or integrity impact. Any WordPress site running Smush 4.2.0 or earlier is affected, and given the plugin's very large install base the potentially exposed population is substantial. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns it roughly a 0.3% probability of exploitation within 30 days, so no active exploitation is currently known.

What to do: Update Smush to the latest available release above version 4.2.0 as soon as practical; if immediate patching is not possible, consider temporarily deactivating the plugin or rate-limiting/throttling unauthenticated requests to the site to blunt resource-exhaustion attacks. With no public PoC and low EPSS there is no evidence of active exploitation, but sites with strict uptime requirements should prioritize the upgrade and verify the installed Smush version in the WordPress plugin list.

Affected
WPMU DEV Smush Image Compression and Optimization (WordPress plugin)<= 4.2.0
Estimated exposure
mass≈1,000,000+ WordPress sites (plugin has historically shown ~1M active installs on WordPress.org) — Estimate based on the plugin's WordPress.org active-install count, which has long been around one million sites, though only installs running versions at or below 4.2.0 with the vulnerable path reachable are actually exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.

Ecosystems
WordPress
Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.