CVE-2026-100196
Received Received - Intake

Stored XSS in LazyLoad WordPress Plugin

Vulnerability report for CVE-2026-100196, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment_content (rendered inline into the page HTML)' parameter in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress core's wp_kses_data allow-list does not strip the crafted payload on save because it uses only permitted tags and attributes; the event handler is concealed inside a broken attribute region and is only promoted to a real DOM attribute by the plugin's render-time str_replace transformation. Additionally, a site administrator must approve the crafted comment before the payload is served to other visitors.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_media LazyLoad Plugin – Lazy Load Images, Videos, and Iframes 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The LazyLoad Plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the 'comment_content' parameter. This allows unauthenticated attackers to inject malicious scripts into pages. The payload is concealed within a broken attribute and only activated by the plugin's render-time transformation. A site administrator must approve the crafted comment before it affects other users.

Detection Guidance

This vulnerability involves stored XSS via malicious comments in the LazyLoad plugin. To detect it, inspect WordPress comments for unusual content, especially those containing script tags or event handlers. Check the plugin version; if it's 2.4.0 or lower, the site is vulnerable. Use WordPress admin tools to review pending comments for suspicious payloads.

Impact Analysis

This vulnerability allows attackers to inject malicious scripts into your WordPress site. If a user visits an infected page, the script can execute, potentially stealing cookies, session tokens, or sensitive data. It could also redirect users to malicious sites or perform actions on their behalf without consent.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR and HIPAA requirements for protecting user data. If exploited, it may result in unauthorized access to personal or health information, leading to legal penalties, fines, and reputational damage for organizations.

Mitigation Strategies

Immediately update the LazyLoad plugin to the latest version, which addresses the XSS flaw. If updating isn't possible, disable the plugin temporarily. Review and delete any suspicious comments in the WordPress admin panel. Consider enabling strict input validation for comments and implementing a web application firewall to block XSS attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100196. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart