Cross-Site Request Forgery Vulnerability in Optimole Plugin for WordPress
CVE-2026-11784

4.3MEDIUM

What is CVE-2026-11784?

The Optimole plugin for WordPress has a Cross-Site Request Forgery vulnerability affecting all versions up to 4.2.6. This flaw arises from inadequate nonce validation in the replace_file function, allowing unauthenticated attackers to potentially overwrite media attachments. They can achieve this by crafting a malicious multipart POST request that targets attachments editable by an unsuspecting user, provided that the attacker successfully tricks a site administrator or a user with Author-level privileges into executing the forged request. The vulnerability emphasizes the need for strong nonce validation to prevent unauthorized media manipulations.

Affected Version(s)

Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization 0 <= 4.2.6

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alexandru Bucur
.