🔐 CVE Alert

CVE-2026-100196

HIGH 7.2

LazyLoad Plugin <= 2.4.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment_content (rendered inline into the page HTML)' parameter in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress core's wp_kses_data allow-list does not strip the crafted payload on save because it uses only permitted tags and attributes; the event handler is concealed inside a broken attribute region and is only promoted to a real DOM attribute by the plugin's render-time str_replace transformation. Additionally, a site administrator must approve the crafted comment before the payload is served to other visitors.

CWE CWE-79
Vendor wp_media
Product lazyload plugin – lazy load images, videos, and iframes
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for wp_media lazyload plugin – lazy load images, videos, and iframes

Be the first to know when new high vulnerabilities affecting wp_media lazyload plugin – lazy load images, videos, and iframes are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

wp_media / LazyLoad Plugin – Lazy Load Images, Videos, and Iframes
0 ≤ 2.4.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/af1060c6-9247-4059-ad6e-993fb7cee6d4?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/rocket-lazy-load/tags/2.4.0/src/Dependencies/RocketLazyload/Image.php#L118 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/rocket-lazy-load/tags/2.4.0/src/Dependencies/RocketLazyload/Image.php#L115 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/rocket-lazy-load/tags/2.4.0/src/Dependencies/RocketLazyload/Image.php#L116 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/rocket-lazy-load/tags/2.4.0/src/Dependencies/RocketLazyload/Image.php#L70 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/rocket-lazy-load/tags/2.4.0/src/Subscriber/LazyloadSubscriber.php#L326 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/rocket-lazy-load/tags/2.4.0/src/Subscriber/LazyloadSubscriber.php#L313 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/rocket-lazy-load/tags/2.4.0/src/Subscriber/LazyloadSubscriber.php#L82 wordpress.org: https://wordpress.org/plugins/rocket-lazy-load/ plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?reponame=&new=3730807%40rocket-lazy-load%2Ftags%2F2.4.1&old=3380138%40rocket-lazy-load%2Ftags%2F2.4.0

Credits

theviper17y