CVE-2026-81285
massUnauthenticated DoS in Smush Image Compression and Optimization WordPress Plugin
CVE-2026-81285 is an unauthenticated denial-of-service vulnerability (CWE-770, allocation of resources without limits or throttling) in the Smush Image Compression and Optimization WordPress plugin, affecting all versions up to and including 4.2.0. Because the issue is reachable over the network without authentication or user interaction (per the CVSS vector AV:N/AC:L/PR:N/UI:N), a remote attacker can repeatedly trigger resource allocation without limits. The impact is availability only: a successful attack can exhaust server resources and leave the affected WordPress site slow or unresponsive, with no confidentiality or integrity impact. Any WordPress site running Smush 4.2.0 or earlier is affected, and given the plugin's very large install base the potentially exposed population is substantial. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns it roughly a 0.3% probability of exploitation within 30 days, so no active exploitation is currently known.
What to do: Update Smush to the latest available release above version 4.2.0 as soon as practical; if immediate patching is not possible, consider temporarily deactivating the plugin or rate-limiting/throttling unauthenticated requests to the site to blunt resource-exhaustion attacks. With no public PoC and low EPSS there is no evidence of active exploitation, but sites with strict uptime requirements should prioritize the upgrade and verify the installed Smush version in the WordPress plugin list.
| WPMU DEV Smush Image Compression and Optimization (WordPress plugin) | <= 4.2.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-770
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.