Junglewise Threat Intelligence

CVE-2026-2390: WordPress Powerkit Stored Cross-Site Scripting in Lazy Load module

CVE-2026-2390 · Severity: medium · CVSS 6.4 · Published 2026-09-07

Technologies: Powerkit.

Executive brief

The Powerkit plugin for WordPress, widely used for site performance optimization, contains a flaw in its Lazy Load image processing feature that allows users with contributor-level permissions to inject malicious scripts into pages. When other users visit an affected page, the injected script automatically executes in their browser, potentially compromising their session, stealing credentials, or spreading malware through the site.

Technical details

This Stored Cross-Site Scripting (XSS) vulnerability exists in the 'content_process_images' function within the Lazy Load module, which uses a flawed regex-based HTML attribute parser. The vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary JavaScript code into page content. The injected payload persists in the database and executes in the browsers of all visitors viewing the compromised page. The vulnerability affects all versions up to and including 3.0.4, and patches addressing the regex parsing flaw should be available from the plugin vendor.

Affected products

  • Powerkit Powerkit up to and including 3.0.4

Timeline

  • 2026-09-07: disclosed

References