Theme developer has been contacted regarding the XSS vulnerability, and the Theme has been suspended in the directory pending the issue being fixed.
Regarding the Theme’s handling of custom headers: the Theme doesn’t claim to support the Custom Header Image feature; rather, it has a custom logo option. This is acceptable, because custom header images and logo images are two different things.
For future reference when searching for Themes: if you want a Theme that supports Custom Header Images, look for Themes with the “custom-header” keyword. Any Theme with that keyword uses the Custom Header image feature, and does so via implementing the core method for that feature.