Stored Cross-Site Scripting Vulnerability in Buzz Comments Plugin for WordPress
CVE-2026-6041
4.4MEDIUM
What is CVE-2026-6041?
The Buzz Comments plugin for WordPress is subject to a Stored Cross-Site Scripting vulnerability through the 'Custom Buzz Avatar' feature in versions up to and including 0.9.4. This security flaw arises from inadequate input sanitization and output escaping protocols. Authenticated attackers with Administrator-level access can exploit this weakness to inject malicious web scripts, which will be executed when users access the plugin settings page, potentially compromising user safety and the overall integrity of the website.
Affected Version(s)
Buzz Comments 0 <= 0.9.4