Stored Cross-Site Scripting Vulnerability in Buzz Comments Plugin for WordPress
CVE-2026-6041

4.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 April 2026

What is CVE-2026-6041?

The Buzz Comments plugin for WordPress is subject to a Stored Cross-Site Scripting vulnerability through the 'Custom Buzz Avatar' feature in versions up to and including 0.9.4. This security flaw arises from inadequate input sanitization and output escaping protocols. Authenticated attackers with Administrator-level access can exploit this weakness to inject malicious web scripts, which will be executed when users access the plugin settings page, potentially compromising user safety and the overall integrity of the website.

Affected Version(s)

Buzz Comments 0 <= 0.9.4

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Nur Ibnu Hubab
.