The LazyLoad Plugin for WordPress up to version 2.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) due to improper sanitization of the comment_content parameter, allowing attackers to inject malicious scripts that execute upon administrator approval.
LazyLoad Plugin – Lazy Load Images, Videos, and Iframes
web-application
xss
wordpress
2t
1c