Vendor
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the LazyLoad Background Mutator, allowing unauthenticated attackers to execute arbitrary scripts after moderator approval.