CVE-2026-105884: WordPress Rocket Lazy Load plugin <= 2.4.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media Rocket Lazy Load rocket-lazy-load allows Stored XSS.This issue affects Rocket Lazy Load: from n/a through 2.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/rocket-lazy-loadto a version that resolves this vulnerability.Fixed in 2.4.1
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges and user interaction. The attack can be conducted over the network with low attack complexity.
Is this a stored or reflected XSS issue?
This is a stored XSS vulnerability. Injected script content may persist and execute when a user views the affected generated page content.
Which versions are affected?
Rocket Lazy Load versions through 2.4.0 are affected. The available data does not identify a fixed version.