Impact
The vulnerability allows an unauthenticated attacker to inject arbitrary JavaScript into comments that are later stored and served to site visitors. The injected script is executed after the Lazy Load Images feature processes background images, causing code to run whenever a page containing the malicious comment is viewed. This can lead to session hijacking, defacement, or data theft, compromising the confidentiality, integrity, and availability of site content.
Affected Systems
WordPress sites using the W3 Total Cache plugin version 2.10.5 or earlier are affected. The issue exists only in the Lazy Load Images module when the "Process background images" option is enabled and comments are approved by a moderator.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability. Although the EPSS score is not available, the requirement for unauthenticated access and pre‑approved comments lowers the likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but can be leveraged by attackers who gain sufficient comment moderation authority. Attackers would exploit the path by posting a comment with malicious payload and having it approved, after which any reader of the affected page will execute the script.
OpenCVE Enrichment