WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Smush – Image Optimization, Compression, Lazy Load, WebP & CDN

Compress and optimize images, enable lazy load, serve WebP & AVIF, and speed up your site with a global image CDN.

7Reported vulnerabilities
9.8Highest CVSS score
4.3.0Latest version
1,000,000+Active installs

What to do now

Update Smush – Image Optimization, Compression, Lazy Load, WebP & CDN to 4.3.2 or later. 7 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 10, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
WF-53b5a052-6e84-4eb5-a7f4-4e32f757f4d6 Critical 9.8 2.9.1 and earlier 3.0.0 December 10, 2018
WF-15654ff3-2e61-44d2-ae3f-4a353db320cb High 8.8 3.0.0 and earlier 3.0.1 December 10, 2018
CVE-2017-15079 High 7.5 2.5% 2.7.5 and earlier 2.7.6 October 6, 2017
CVE-2026-81285 High 7.5 0.3% 4.2.0 and earlier 4.3.0 August 27, 2026
CVE-2026-19223 High 7.2 0.4% Before 4.3.2 4.3.2 August 27, 2026
CVE-2023-3352 Medium 4.3 0.3% 0 to 3.16.4 (inclusive) 3.16.5 June 21, 2024
CVE-2025-22288 Medium 4.1 0.3% 0 to 3.17.0 (inclusive) 3.17.1 November 6, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.