Junglewise Threat Intelligence

CVE-2026-2300: BJ Lazy Load WordPress plugin stored XSS in filter_images

CVE-2026-2300 · Severity: medium · CVSS 6.4 · Published 2026-05-12

Executive brief

BJ Lazy Load is a WordPress plugin used to improve website performance by delaying the loading of images until they are visible to the user. A security flaw in this plugin allows users with basic contributor permissions to inject malicious scripts into website pages. If exploited, these scripts will run automatically in the browsers of any visitors who view the affected pages, potentially leading to unauthorized actions or data theft.

Technical details

The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to improper handling of HTML attribute boundaries within the filter_images() function. The vulnerability stems from the use of regex-based HTML processing (preg_replace) when replacing 'src' attributes, which fails to properly isolate attribute values. An authenticated attacker with Contributor-level permissions or higher can craft malicious content within a 'class' attribute that is subsequently promoted to a functional DOM attribute during processing. This results in the storage of arbitrary JavaScript that executes in the context of any user viewing the compromised page. The issue exists in all versions up to and including 1.0.9.

Affected products

  • BJ Lazy Load BJ Lazy Load Up to and including 1.0.9

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References