Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Unauthenticated Information Exposure via Failed Form Submissions

Low 3.7 CWE-200Fixed in 2.10.1
ID
WPSEC-2026-0579
Plugin
BuddyForms (buddyforms)
Affected
from 2.5.9 before 2.10.1
Remediation
Update to 2.10.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms on WPSec AttackSurface
Fix released
Published

Description

The BuddyForms plugin for WordPress is vulnerable to Information Exposure in versions 2.5.9 up to, and including, 2.10.0. When a form with AJAX submission disabled fails validation, the plugin stores the submitted values under a name built only from the form slug and the entry ID, and loads them into any request that carries those two values, without verifying the nonce. Because logged-out visitors of a form share the same entry ID, this makes it possible for unauthenticated attackers to view the values another visitor entered in a failed submission of such a form.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0