BJ Lazy Load <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom HTML Block
medium
The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in all versions up to, and including, 1.0.9. This is due to the use of regex-based HTML processing (`preg_replace`) that does not properly handle HTML attribute boundaries when replacing `src` attribute...
- CVSS:
- 6.4
- Affected:
- up to 1.0.9
- Fix:
- No patched version reported
- Disclosed:
- May 11, 2026
CVE-2026-2300 on NVD →
BJ Lazy Load [bj-lazy-load] < 1.0
unknown
Update the plugin.
An unknown person discovered and reported this Remote File Inclusion vulnerability in WordPress BJ Lazy Load Plugin. This could allow a malicious actor to get a website to load an external website or script which will then be executed on the website. This could allow the malicious actor to create bac...
- Affected:
- up to 1.0
- Fixed in:
- 1.0
- Disclosed:
- Sep 2, 2023
BJ Lazy Load [bj-lazy-load] < 1.0
unknown
[en] The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.
- Affected:
- up to 1.0
- Fixed in:
- 1.0
- Disclosed:
- Sep 25, 2019
CVE-2015-9415 on NVD →
BJ Lazy Load < 1.0 - Remote File Inclusion via TimThumb
critical
The BJ Lazy Load plugin v0.7.5 for WordPress has Remote File Inclusion vulnerability via TimThumb.
- CVSS:
- 9.8
- Affected:
- 0.7.5 – 0.7.5
- Fixed in:
- 1.0
- Disclosed:
- Sep 2, 2015
CVE-2015-9415 on NVD →
BJ Lazy Load [bj-lazy-load] < 1.0
unknown
This vulnerability allows any visitor to upload any kind of file in your website.
Update the plugin.
- Affected:
- up to 1.0
- Fixed in:
- 1.0
- Disclosed:
- Sep 2, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database