{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/lazyload-plugin--lazy-load-images-videos-and-iframes--2.4.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:lazyload_plugin_lazy_load_images_videos_and_iframes:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-100196"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LazyLoad Plugin – Lazy Load Images, Videos, and Iframes (\u003c= 2.4.0)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe LazyLoad Plugin (version 2.4.0 and below) for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability. The vulnerability resides in how the plugin handles the 'comment_content' parameter during render-time. While WordPress core's 'wp_kses_data' function attempts to sanitize input, the plugin performs an additional 'str_replace' transformation on the content before output. This transformation promotes concealed event handlers within broken attribute regions into active, executable DOM attributes.\u003c/p\u003e\n\u003cp\u003eBecause the script is injected via comment fields, an attacker must submit a comment containing the crafted payload. The vulnerability is only realized if a site administrator subsequently approves the comment, at which point the malicious payload is served to other users visiting the site. This allows unauthenticated attackers to execute arbitrary JavaScript in the context of other site visitors or administrative sessions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting a public-facing WordPress comment submission form.\u003c/li\u003e\n\u003cli\u003eThe 'comment_content' parameter is populated with a payload containing concealed event handlers inside malformed HTML attributes to bypass 'wp_kses_data'.\u003c/li\u003e\n\u003cli\u003eThe malicious comment is submitted to the target WordPress instance.\u003c/li\u003e\n\u003cli\u003eThe WordPress site administrator reviews the pending comment queue.\u003c/li\u003e\n\u003cli\u003eThe administrator approves the crafted comment, causing it to be committed to the site database.\u003c/li\u003e\n\u003cli\u003eThe LazyLoad plugin processes the stored comment using its 'str_replace' transformation, converting the concealed handler into an active executable tag.\u003c/li\u003e\n\u003cli\u003eA legitimate user or administrator views the page containing the comment.\u003c/li\u003e\n\u003cli\u003eThe injected script executes in the user's browser, enabling session hijacking or further client-side exploitation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of any user who views the infected page. This can lead to account takeover, unauthorized administrative actions, or the theft of session cookies if an administrator views the comment. Given that this requires manual administrative approval, it serves as a persistent, high-impact vector for social engineering or site-wide malware distribution.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the LazyLoad Plugin to a version beyond 2.4.0 immediately. If an update is unavailable, disable the plugin or restrict comment posting to authenticated users only. Review current comment queues for suspicious payloads containing malformed HTML attributes or unusual event handlers.\u003c/p\u003e\n","date_modified":"2026-10-10T07:52:14Z","date_published":"2026-10-10T07:52:14Z","id":"https://feed.craftedsignal.io/briefs/2026-10-lazyload-xss/","summary":"The LazyLoad Plugin for WordPress up to version 2.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) due to improper sanitization of the comment_content parameter, allowing attackers to inject malicious scripts that execute upon administrator approval.","title":"Stored XSS in LazyLoad Plugin for WordPress via Comment Injection","url":"https://feed.craftedsignal.io/briefs/2026-10-lazyload-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - LazyLoad Plugin – Lazy Load Images, Videos, and Iframes (\u003c= 2.4.0)","version":"https://jsonfeed.org/version/1.1"}