CVE-2025-7732

Lazy Load for Videos <= 2.18.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via data-video-title and href Attributes

The Lazy Load for Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lazy‑loading handlers in all versions up to, and including, 2.18.7 due to insufficient input sanitization and output escaping. The plugin’s JavaScript registration handlers read the client‑supplied 'data-video-title' and 'href' attributes, decode HTML entities by default, and pass them directly into DOM sinks without any escaping or validation. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 1,804 live websites that are affected by CVE-2025-7732.

Run a Free Instant Scan




Affected Software

Product  Lazy Load For Videos
Category Wordpress Plugins
Vulnerable Domains1,804 live websites (54% of Lazy Load For Videos install base)
Vulnerable Versions
  • from 0 through 2.18.7
Vulnerable Versions Count36 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 27, 2025
  • Updated - Aug 27, 2025

Credits

  • Craig Smith (finder)

Website Distribution by Country

Number of websites using CVE-2025-7732
United States758 websites



Germany232 websites
Russia82 websites
GB76 websites
France59 websites
Sweden53 websites
Japan52 websites
Spain39 websites
Netherlands34 websites
Australia30 websites

Website Distribution by TLD

Number of websites using CVE-2025-7732
.com925 websites
.org144 websites
.de119 websites
.ru65 websites
.net56 websites
.co.uk45 websites
.nl25 websites
.fr24 websites
.com.br24 websites
.com.au23 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-7732

Top websites that are affected by CVE-2025-7732. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States**,***
*********.com United States**,***
*****************.***.au Australia**,***
******************.com Cyprus**,***
************.org Canada**,***
*****.org United States**,***
*****************.com Canada***,***
********.com United States***,***
***.org United States***,***
***************.com United States***,***
See full domain list

FAQ

CVE-2025-7732 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Lazy Load For Videos
A total of 1,804 websites have been identified as vulnerable to CVE-2025-7732, based on global website indexing conducted by WebTechSurvey.
The Lazy Load For Videos is affected by the CVE-2025-7732 vulnerability.
Lazy Load For Videos versions up to and including 2.18.7 are vulnerable to CVE-2025-7732.