Stored Cross-Site Scripting in Lazy Load Images Plugin for WordPress
CVE-2026-100196
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-100196?
The Lazy Load Images, Videos, and Iframes plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping in the 'comment_content' parameter. This loophole permits unauthorized attackers to insert arbitrary scripts into web pages, which are triggered when users visit the manipulated pages. The WordPress core's wp_kses_data allow-list fails to erase the malicious payload upon saving since it only filters through permitted tags and attributes. The payload's concealment in a flawed attribute area, coupled with the plugin's str_replace operation at render time, exacerbates the issue. Furthermore, it requires an approval from a site administrator for the malicious comment to be delivered to other users.
Affected Version(s)
LazyLoad Plugin β Lazy Load Images, Videos, and Iframes 0 <= 2.4.0