Vulnerabilities
Report: CVE-2026-6427 - a3 Lazy Load <= 2.7.6 - authenticated (contributor+) stored cross-site scripting
CVE ID :CVE-2026-6427 Published : May 28, 2026, 6:45 a.m. | 1 hour, 10 minutes ago Description :The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.7.6 This is due to a regex bug in the _filter_videos() method that breaks HTML attribute quoting when processing crafted Severity: