OVERVIEW CVE-2026-6041 is a Stored Cross-Site Scripting vulnerability in the Buzz Comments plugin for WordPress affecting all versions through 0.9.4. The flaw exists in the Custom Buzz Avatar plugin setting due to insufficient input sanitization and output escaping, allowing malicious code injection into plugin settings pages. SEVERITY The vulnerability carries a CVSS 3.1 score of 4.4 (Medium) with a network-based attack vector requiring high privilege and administrative access. While the attack complexity is high and requires authenticated Administrator-level credentials, successful exploitation could result in low-impact confidentiality and integrity compromises when users access the plugin settings page. The low EPSS score of 0.00008 indicates this is not a widespread threat in the wild. EXPLOITATION STATUS There is no current evidence of active exploitation. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and has not been added to any active threat hot lists. No public exploit code is currently available. The modest FAUCET risk score of 30 out of 100 and minimal community attention suggest this vulnerability remains largely dormant in the threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Mixer2 | Buzz Comments | >= 0, <= 0.9.4CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.