Vendor
The W3 Total Cache plugin for WordPress versions up to 2.10.3 is vulnerable to Stored Cross-Site Scripting when the Lazy Load Images feature is enabled, allowing unauthenticated attackers to inject malicious scripts via comment author names.