
Proof-of-concept exploit for CVE-2026-11784, a CSRF vulnerability in the Optimole WordPress plugin allowing arbitrary file overwrite via missing nonce validation.
A Cross-Site Request Forgery (CSRF) vulnerability in the Optimole plugin for WordPress (versions <= 4.2.5) allows unauthenticated attackers to silently overwrite existing media library assets via the wp_ajax_optml_replace_file AJAX action due to a lack of nonce validation.
The vulnerability resides in inc/attachment_edit.php within the Optml_Attachment_Edit::replace_file() method. While the function implements an authorization check using current_user_can('edit_post', $id), it entirely omits an explicit anti-CSRF token verification (check_ajax_referer).
A naive CSRF attack passing a text string as a mock image fails because WordPress validates image integrity using GD Graphics Library / ImageMagick routines. To achieve a valid PoC, the exploit payload programmatically constructs a mathematically sound 1x1 JPEG binary via JavaScript Uint8Array and a Base64 string before submitting the multipart form.
The exploit script can be found in the /exploit directory.