# Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Reflected Cross-Site Scripting via 'error_msg_*' Parameters

- **ID:** WPSEC-2026-0580
- **Plugin:** BuddyForms (`buddyforms`), https://wordpress.org/plugins/buddyforms/
- **Affected versions:** from 2.5.30 before 2.10.1
- **Fixed in:** 2.10.1 (Update to 2.10.1 or later.)
- **Severity:** Medium 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/buddyforms
- **Fix released:** 2026-10-03
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0580/

## Description

The BuddyForms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via error_msg_* query parameters on the BuddyForms login form in all versions up to, and including, 2.10.0. This is due to insufficient input sanitization and output escaping: the error messages were read from the URL and added to the login form HTML without escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute if they can trick a user into clicking a crafted link.

## References

- https://wpsec.com/vuln/WPSEC-2026-0580/
- https://plugins.svn.wordpress.org/buddyforms/tags/2.10.1/
- https://wordpress.org/plugins/buddyforms/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0580/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
