Impact
The LazyLoad Plugin stores arbitrary web scripts inside user comments without proper sanitization, allowing unauthenticated attackers to inject malicious payloads that execute whenever a page containing the comment is viewed. The flaw arises from the plugin’s rendering logic, which performs a string replacement that turns a broken attribute region into a valid DOM attribute, bypassing WordPress’s built‑in safety net. This stored XSS grants an attacker the ability to run client‑side code in every user’s browser session that visits the affected page, potentially leading to credential theft, session hijacking, or malicious redirection.
Affected Systems
All installations of the LazyLoad Plugin – Lazy Load Images, Videos, and Iframes with a version of 2.4.0 or earlier are affected. The CVE documentation does not specify a patch is available, so the vulnerability remains in those releases until a vendor update.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. Although an EPSS value is not available, the lack of exploitation references and the fact that the plugin is widely installed make the expected risk moderate‑high. The attack does not require authentication to submit the comment, but the comment must be approved by a site administrator before it is displayed, meaning an attacker must either lure an admin into approving a malicious comment or conduct a targeted social‑engineering attack. Once approved, the payload is served to all site visitors, creating a broad impact without privilege escalation on the WordPress instance.
OpenCVE Enrichment