Impact
The Blogger Buzz theme contains a stored cross‑site scripting flaw that fails to neutralize user input when generating web pages. An attacker who can submit content to the site can embed malicious script that executes in the browsers of any visitor, enabling session hijacking, defacement, or the delivery of malware.
Affected Systems
Sparklewpthemes Blogger Buzz theme versions 1.2.6 and earlier are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the flaw via web interfaces that accept user content, leveraging the stored XSS to run arbitrary scripts in a victim’s browser. No further conditions for exploitation are mentioned in the advisory.
OpenCVE Enrichment
EUVD