<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:wordpress:lazyload_plugin_lazy_load_images_videos_and_iframes:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3awordpresslazyload_plugin_lazy_load_images_videos_and_iframes/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:52:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3awordpresslazyload_plugin_lazy_load_images_videos_and_iframes/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in LazyLoad Plugin for WordPress via Comment Injection</title><link>https://feed.craftedsignal.io/briefs/2026-10-lazyload-xss/</link><pubDate>Sat, 10 Oct 2026 07:52:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-lazyload-xss/</guid><description>The LazyLoad Plugin for WordPress up to version 2.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) due to improper sanitization of the comment_content parameter, allowing attackers to inject malicious scripts that execute upon administrator approval.</description><content:encoded><![CDATA[<p>The LazyLoad Plugin (version 2.4.0 and below) for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability. The vulnerability resides in how the plugin handles the 'comment_content' parameter during render-time. While WordPress core's 'wp_kses_data' function attempts to sanitize input, the plugin performs an additional 'str_replace' transformation on the content before output. This transformation promotes concealed event handlers within broken attribute regions into active, executable DOM attributes.</p>
<p>Because the script is injected via comment fields, an attacker must submit a comment containing the crafted payload. The vulnerability is only realized if a site administrator subsequently approves the comment, at which point the malicious payload is served to other users visiting the site. This allows unauthenticated attackers to execute arbitrary JavaScript in the context of other site visitors or administrative sessions.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker crafts an HTTP POST request targeting a public-facing WordPress comment submission form.</li>
<li>The 'comment_content' parameter is populated with a payload containing concealed event handlers inside malformed HTML attributes to bypass 'wp_kses_data'.</li>
<li>The malicious comment is submitted to the target WordPress instance.</li>
<li>The WordPress site administrator reviews the pending comment queue.</li>
<li>The administrator approves the crafted comment, causing it to be committed to the site database.</li>
<li>The LazyLoad plugin processes the stored comment using its 'str_replace' transformation, converting the concealed handler into an active executable tag.</li>
<li>A legitimate user or administrator views the page containing the comment.</li>
<li>The injected script executes in the user's browser, enabling session hijacking or further client-side exploitation.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of any user who views the infected page. This can lead to account takeover, unauthorized administrative actions, or the theft of session cookies if an administrator views the comment. Given that this requires manual administrative approval, it serves as a persistent, high-impact vector for social engineering or site-wide malware distribution.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the LazyLoad Plugin to a version beyond 2.4.0 immediately. If an update is unavailable, disable the plugin or restrict comment posting to authenticated users only. Review current comment queues for suspicious payloads containing malformed HTML attributes or unusual event handlers.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>wordpress</category></item></channel></rss>