CVE-2026-2390 is a stored cross-site scripting (XSS) vulnerability in Powerkit, a WordPress plugin, affecting all versions up to and including 3.0.4.
What the vulnerability does
Per the vulnerability record, the flaw is in Powerkit’s Lazy Load module, specifically its content_process_images function, which processes image markup using a regex-based HTML attribute parser. That parser is flawed in a way that lets an attacker inject arbitrary web scripts into a page’s content — the injected script then executes for any user who later views the affected page.
The access level required matters here: exploitation requires Contributor-level access and above — meaning it’s not exploitable by an unauthenticated visitor or a bare subscriber account, but any WordPress site that allows Contributor-role signups (a common setup for multi-author blogs and guest-post workflows) has a population of users who could potentially exploit this. Once injected, the stored script executes for every subsequent visitor to the affected page, including site administrators — a common privilege-escalation path for stored XSS in CMS plugins (a Contributor triggers a payload that later executes in an Editor’s or Administrator’s browser session).
Confidence
This traces to a specific plugin function and root cause (a flawed regex-based HTML parser) consistent with how Wordfence’s vulnerability database documents WordPress plugin CVEs — confidence is high.
What we don’t yet have
We don’t have a confirmed patched Powerkit version in the available record. Sites running Powerkit should check the plugin’s WordPress.org changelog directly for a release beyond 3.0.4 addressing this issue before assuming the current latest version is safe.
Why this matters
WordPress plugin vulnerabilities exploitable at the Contributor role are frequently underestimated because Contributor is a low-privilege role by design — but any site accepting outside contributors (guest bloggers, freelance writers with direct CMS access) has real users at that access level, and a stored XSS payload that later executes in an editor’s or admin’s browser session can lead to full site compromise. Sites running Powerkit with open or semi-open Contributor registration should restrict content review before publication and update the plugin as soon as a fix is confirmed available.
Frequently Asked Questions
What is CVE-2026-2390? A stored cross-site scripting vulnerability in the Powerkit WordPress plugin (versions up to 3.0.4), exploitable by users with Contributor-level access via a flaw in the Lazy Load module’s image-processing function.
Which version fixes CVE-2026-2390? Not confirmed in the available record — check the Powerkit plugin’s official changelog for a release beyond 3.0.4.
Is CVE-2026-2390 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.
Data sourced from Wordfence’s vulnerability database, aggregated September 2026. See more vulnerability intelligence.