Impact
The Optimole plugin for WordPress is vulnerable to cross‑site request forgery in all versions 4.2.6 and earlier. A missing or incorrect nonce check on the "optml_replace_file" AJAX action allows an attacker to craft a multipart POST request that overwrites any media attachment a user can edit. This results in unauthorized file replacement, potentially compromising site content and integrity.
Affected Systems
Any WordPress installation running Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization version 4.2.6 or earlier is affected. Administrators or authors who have edit permissions on media files are required to be tricked into performing the forged request.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, while the EPSS score of less than 1% suggests the likelihood of exploitation is currently low, though not absent. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a social‑engineering step to persuade a user with at least author privileges to click a malicious link, after which the forged request can overwrite attachments. If unmitigated, the attacker can replace critical media assets, potentially defacing the site or subverting content.
OpenCVE Enrichment