Description
The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment_content (rendered inline into the page HTML)' parameter in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress core's wp_kses_data allow-list does not strip the crafted payload on save because it uses only permitted tags and attributes; the event handler is concealed inside a broken attribute region and is only promoted to a real DOM attribute by the plugin's render-time str_replace transformation. Additionally, a site administrator must approve the crafted comment before the payload is served to other visitors.
Published: 2026-10-10
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting with site‑wide impact
Action: Patch Now
AI Analysis

Impact

The LazyLoad Plugin stores arbitrary web scripts inside user comments without proper sanitization, allowing unauthenticated attackers to inject malicious payloads that execute whenever a page containing the comment is viewed. The flaw arises from the plugin’s rendering logic, which performs a string replacement that turns a broken attribute region into a valid DOM attribute, bypassing WordPress’s built‑in safety net. This stored XSS grants an attacker the ability to run client‑side code in every user’s browser session that visits the affected page, potentially leading to credential theft, session hijacking, or malicious redirection.

Affected Systems

All installations of the LazyLoad Plugin – Lazy Load Images, Videos, and Iframes with a version of 2.4.0 or earlier are affected. The CVE documentation does not specify a patch is available, so the vulnerability remains in those releases until a vendor update.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity. Although an EPSS value is not available, the lack of exploitation references and the fact that the plugin is widely installed make the expected risk moderate‑high. The attack does not require authentication to submit the comment, but the comment must be approved by a site administrator before it is displayed, meaning an attacker must either lure an admin into approving a malicious comment or conduct a targeted social‑engineering attack. Once approved, the payload is served to all site visitors, creating a broad impact without privilege escalation on the WordPress instance.

Generated by OpenCVE AI on October 10, 2026 at 08:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest available version of the LazyLoad Plugin once a vendor patch is released.
  • If an immediate upgrade is not possible, disable the comment subsystem or require manual approval with CAPTCHA to prevent malicious input.
  • Apply an additional comment‑content filter using WordPress’s wp_kses or a security plugin to ensure comment input is sanitized before storage.

Generated by OpenCVE AI on October 10, 2026 at 08:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment_content (rendered inline into the page HTML)' parameter in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress core's wp_kses_data allow-list does not strip the crafted payload on save because it uses only permitted tags and attributes; the event handler is concealed inside a broken attribute region and is only promoted to a real DOM attribute by the plugin's render-time str_replace transformation. Additionally, a site administrator must approve the crafted comment before the payload is served to other visitors.
Title LazyLoad Plugin <= 2.4.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:14.705Z

Reserved: 2026-09-25T14:49:45.612Z

Link: CVE-2026-100196

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:39.833

Modified: 2026-10-10T07:16:39.833

Link: CVE-2026-100196

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:00:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')