Sceawere
Vulnerability Detail
CVE-2026-100196UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LazyLoad Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- wp_media
- Product
- LazyLoad Plugin – Lazy Load Images, Videos, and Iframes
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment_content (rendered inline into the page HTML)' parameter in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress core's wp_kses_data allow-list does not strip the crafted payload on save because it uses only permitted tags and attributes; the event handler is concealed inside a broken attribute region and is only promoted to a real DOM attribute by the plugin's render-time str_replace transformation. Additionally, a site administrator must approve the crafted comment before the payload is served to other visitors.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T07:16:39.833Z",
"pubdate": "2026-10-10T07:16:39.833Z",
"executiveSummary": "The LazyLoad WordPress plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 2.4.0.\nThe vulnerability originates from inadequate input sanitization and output escaping within the comment_content parameter as it is rendered into the HTML document.\nAn unauthenticated attacker can leverage this flaw to inject arbitrary malicious JavaScript payloads into site pages.\nSuccessful exploitation results in the execution of unauthorized scripts within the browser session of any user who accesses the compromised page.\nWhile WordPress core's wp_kses_data function attempts to filter input, the plugin's internal render-time transformations bypass these security controls.\nA significant requirement for exploitation is that a site administrator must approve the malicious comment, which acts as a gating factor for the payload to be rendered to the public.\nThe potential impact includes session hijacking, unauthorized actions performed on behalf of authenticated users, and unauthorized information disclosure.",
"technicalDetails": "The vulnerability resides in the processing of the 'comment_content' parameter within the LazyLoad plugin. Although the input passes through the WordPress 'wp_kses_data' allow-list, the security filter fails to neutralize the payload because the malicious attributes are initially structured as non-executable, broken attribute regions that bypass standard sanitization logic.\nThe exploitation relies on a render-time 'str_replace' transformation executed by the plugin. During the rendering phase, this function modifies the HTML structure, effectively promoting the previously inert or broken attribute regions into active, functional DOM attributes. This mechanism enables an attacker to inject event handlers (e.g., 'onerror' or 'onload') that become executable after the transformation.\nThe attack flow proceeds as follows: First, the unauthenticated attacker submits a crafted comment containing the payload, which is designed to pass initial server-side validation. Second, the comment is stored in the WordPress database. Third, a site administrator must approve the comment, an action which transitions the payload from a pending state to a live state. Finally, whenever a visitor accesses the page where the comment is displayed, the plugin's 'str_replace' logic triggers, transforming the payload into valid HTML attributes and executing the malicious JavaScript in the victim's browser context.\nThe technical root cause is the reliance on insecure string manipulation during output rendering rather than utilizing proper HTML parsing and context-aware escaping. By altering the DOM structure after sanitization, the plugin subverts the security guarantees provided by 'wp_kses_data'.\nAffected versions include all releases up to and including 2.4.0. The exploit requires no authentication from the attacker, though it requires the target site to have comment moderation enabled and an administrator to approve the comment, effectively moving the payload into a globally rendered state. Post-exploitation, the malicious script executes with the privileges of the victim, allowing for further interaction with the WordPress environment."
}