Vulnerabilities / Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms / WPSEC-2026-0580
Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Reflected Cross-Site Scripting via 'error_msg_*' Parameters
Medium 6.1
CWE-79Fixed in 2.10.1
- ID
- WPSEC-2026-0580
- Plugin
- BuddyForms (buddyforms)
- Affected
- from 2.5.30 before 2.10.1
- Remediation
- Update to 2.10.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
- Attack surface
- Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms on WPSec AttackSurface
- Fix released
- Published
Description
The BuddyForms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via error_msg_* query parameters on the BuddyForms login form in all versions up to, and including, 2.10.0. This is due to insufficient input sanitization and output escaping: the error messages were read from the URL and added to the login form HTML without escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute if they can trick a user into clicking a crafted link.
References
- https://wpsec.com/vuln/WPSEC-2026-0580/
- https://plugins.svn.wordpress.org/buddyforms/tags/2.10.1/
- https://wordpress.org/plugins/buddyforms/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS