Cross-Site Request Forgery Vulnerability in Optimole Plugin for WordPress
CVE-2026-11784
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 June 2026
What is CVE-2026-11784?
The Optimole plugin for WordPress has a Cross-Site Request Forgery vulnerability affecting all versions up to 4.2.6. This flaw arises from inadequate nonce validation in the replace_file function, allowing unauthenticated attackers to potentially overwrite media attachments. They can achieve this by crafting a malicious multipart POST request that targets attachments editable by an unsuspecting user, provided that the attacker successfully tricks a site administrator or a user with Author-level privileges into executing the forged request. The vulnerability emphasizes the need for strong nonce validation to prevent unauthorized media manipulations.
Affected Version(s)
Optimole β Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization 0 <= 4.2.6