Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Reflected Cross-Site Scripting via 'error_msg_*' Parameters

Medium 6.1 CWE-79Fixed in 2.10.1
ID
WPSEC-2026-0580
Plugin
BuddyForms (buddyforms)
Affected
from 2.5.30 before 2.10.1
Remediation
Update to 2.10.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms on WPSec AttackSurface
Fix released
Published

Description

The BuddyForms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via error_msg_* query parameters on the BuddyForms login form in all versions up to, and including, 2.10.0. This is due to insufficient input sanitization and output escaping: the error messages were read from the URL and added to the login form HTML without escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute if they can trick a user into clicking a crafted link.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0