Medium 6.4
2025-12-13< 2.7.6
a3 Lazy Load <= 2.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Minimum safe version
2.7.6
Update to 2.7.6 or later to address 3 fixable vulnerabilities
a3 Lazy Load <= 2.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
a3rev Multiple Plugins <= Various Versions - Cross-Site Request Forgery to Settings Changes
a3 Lazy Load <= 2.6.0 - Cross-Site Request Forgery to Settings Reset