Stored Cross-Site Scripting Vulnerability in a3 Lazy Load Plugin for WordPress
CVE-2026-6427

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 May 2026

What is CVE-2026-6427?

The a3 Lazy Load plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability across all versions up to and including 2.7.6. This flaw arises from a regex oversight in the _filter_videos() method that improperly handles HTML attribute quoting when parsing crafted elements. Consequently, malicious users with Contributor-level permissions can exploit this by injecting a specially crafted tag. This tag includes a src attribute that carries an embedded class=' substring, which manipulates the class-replacement regex, allowing an attacker to influence the HTML5 parser's quote boundaries. As a result, attacker-controlled text can escape the confines of a quoted attribute, enabling execution of arbitrary scripts in the browsers of any user—including administrators—viewing the post.

Affected Version(s)

a3 Lazy Load 0 <= 2.7.6

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Youcef Hamdani
.