Executive brief
Bloggie is a WordPress theme used to build blog websites. A cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts into pages, potentially stealing visitor data or hijacking user accounts. The attack requires user interaction, such as clicking a malicious link, but can affect thousands of websites at once.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) issue accessible to unauthenticated attackers in the Bloggie WordPress theme through version 2.0.8. While the title mentions CSRF, the core vulnerability is XSS that can be exploited via user interaction (clicking a malicious link or visiting a crafted page). This allows attackers to inject malicious JavaScript into the site that executes in visitors' browsers, potentially stealing session cookies, harvesting credentials, or redirecting users to phishing pages. No official patch has been released as of the advisory date; mitigation via Web Application Firewall rules is available from Patchstack.
Affected products
- Themefy Bloggie through 2.0.8
Timeline
- 2025-03-20: disclosed: Reported to Patchstack
- 2025-05-19: advisory: Published on Patchstack
- 2025-12-31: other: NVD entry published