Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-11784-Optimole-CSRF — Proof-of-concept exploit for CVE-2026-11784, a CSRF vulnerability in the Optimole WordPress plugin allowing arbitrary file overwrite via missing nonce validation. | Kitploit
Tools/GitHubGitHub/alexmihailengineer/cve-2026-11784-optimole-csrf
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubalexmihailengineer/cve-2026-11784-optimole-csrf

CVE-2026-11784-Optimole-CSRF

Proof-of-concept exploit for CVE-2026-11784, a CSRF vulnerability in the Optimole WordPress plugin allowing arbitrary file overwrite via missing nonce validation.

View Repository
43 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-11784: CSRF to Arbitrary File Overwrite in Optimole WordPress Plugin

Summary

A Cross-Site Request Forgery (CSRF) vulnerability in the Optimole plugin for WordPress (versions <= 4.2.5) allows unauthenticated attackers to silently overwrite existing media library assets via the wp_ajax_optml_replace_file AJAX action due to a lack of nonce validation.

  • CVE ID: CVE-2026-11784
  • Vulnerability Type: Cross-Site Request Forgery (CSRF)
  • Affected Plugin: Optimole – Optimize Images
  • Remediation Version: 4.2.6
  • Discoverer: Alexandru Bucur

Technical Analysis

The vulnerability resides in inc/attachment_edit.php within the Optml_Attachment_Edit::replace_file() method. While the function implements an authorization check using current_user_can('edit_post', $id), it entirely omits an explicit anti-CSRF token verification (check_ajax_referer).

The Image Validation Bypass

A naive CSRF attack passing a text string as a mock image fails because WordPress validates image integrity using GD Graphics Library / ImageMagick routines. To achieve a valid PoC, the exploit payload programmatically constructs a mathematically sound 1x1 JPEG binary via JavaScript Uint8Array and a Base64 string before submitting the multipart form.

Proof of Concept

The exploit script can be found in the /exploit directory.

Impact

  • Data Integrity Loss: High-value media elements (logos, documents) can be overwritten.
  • XSS Escalation: If the target media type allows SVG or executable execution vectors, this can easily lead to a full Stored Cross-Site Scripting exploit and complete site takeover.

Timeline

  • May 14, 2026: Initial discovery & submission.
  • June 2026: Validated and assigned CVE-2026-11784.
  • June 2026: Public Disclosure.
Download Tool