{
 "id": "WPSEC-2026-0579",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0579/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0579/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0579/index.md",
 "title": "Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Unauthenticated Information Exposure via Failed Form Submissions",
 "description": "The BuddyForms plugin for WordPress is vulnerable to Information Exposure in versions 2.5.9 up to, and including, 2.10.0. When a form with AJAX submission disabled fails validation, the plugin stores the submitted values under a name built only from the form slug and the entry ID, and loads them into any request that carries those two values, without verifying the nonce. Because logged-out visitors of a form share the same entry ID, this makes it possible for unauthenticated attackers to view the values another visitor entered in a failed submission of such a form.",
 "plugin": {
  "slug": "buddyforms",
  "name": "Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms",
  "full_name": "BuddyForms",
  "wordpress_org": "https://wordpress.org/plugins/buddyforms/",
  "advisories_url": "https://wpsec.com/vuln/plugin/buddyforms/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/buddyforms"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 3.7,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Low"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.5.9",
    "from_inclusive": true,
    "to": "2.10.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.5.9 before 2.10.1"
  ]
 },
 "introduced_in": "2.5.9",
 "fixed_in": "2.10.1",
 "remediation": "Update to 2.10.1 or later.",
 "fix_released": "2026-10-03T21:02:24+00:00",
 "published": "2026-10-07T19:47:10+00:00",
 "updated": "2026-10-07T18:51:22.064072+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0579/",
  "https://plugins.svn.wordpress.org/buddyforms/tags/2.10.1/",
  "https://wordpress.org/plugins/buddyforms/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/buddyforms",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-07"
 }
}