Vulnerabilities / Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms / WPSEC-2026-0582
Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Unauthenticated Missing Authorization to Image Upload via upload_image_from_url AJAX Action
Medium 5.3
CWE-862Fixed in 2.10.1
- ID
- WPSEC-2026-0582
- Plugin
- BuddyForms (buddyforms)
- Affected
- from 2.5.10 before 2.10.1
- Remediation
- Update to 2.10.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
- Attack surface
- Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms on WPSec AttackSurface
- Fix released
- Published
Description
The BuddyForms plugin for WordPress is vulnerable to unauthorized file uploads via the upload_image_from_url AJAX action in all versions up to, and including, 2.10.0. This is due to a missing nonce check and a missing form-level permission check. The accepted file types were also taken from the request instead of the form field settings. This makes it possible for unauthenticated attackers to have the site download remote images and store them as attachments in the media library, regardless of form settings.
References
- https://wpsec.com/vuln/WPSEC-2026-0582/
- https://plugins.svn.wordpress.org/buddyforms/tags/2.10.1/
- https://wordpress.org/plugins/buddyforms/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS