CVE-2026-2390: Powerkit <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy Load Image Processing
The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This is due to the 'contentprocessimages' function using a flawed regex-based HTML attribute parser. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need?
An attacker must be authenticated with a Contributor-level WordPress account or higher. No user interaction is required from the attacker to submit the malicious content.
Who may be impacted after malicious content is published?
Arbitrary web scripts can execute in the browser of any user who accesses an injected page. This can affect users with higher privileges if they view the compromised content.
Which versions should be considered affected?
All Powerkit versions up to and including 3.0.4 are affected according to the available information.