Stored Cross-Site Scripting in Lazy Load Images Plugin for WordPress
CVE-2026-100196

7.2HIGH

What is CVE-2026-100196?

The Lazy Load Images, Videos, and Iframes plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping in the 'comment_content' parameter. This loophole permits unauthorized attackers to insert arbitrary scripts into web pages, which are triggered when users visit the manipulated pages. The WordPress core's wp_kses_data allow-list fails to erase the malicious payload upon saving since it only filters through permitted tags and attributes. The payload's concealment in a flawed attribute area, coupled with the plugin's str_replace operation at render time, exacerbates the issue. Furthermore, it requires an approval from a site administrator for the malicious comment to be delivered to other users.

Affected Version(s)

LazyLoad Plugin – Lazy Load Images, Videos, and Iframes 0 <= 2.4.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17y
.