# Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Unauthenticated Missing Authorization to Image Upload via upload_image_from_url AJAX Action

- **ID:** WPSEC-2026-0582
- **Plugin:** BuddyForms (`buddyforms`), https://wordpress.org/plugins/buddyforms/
- **Affected versions:** from 2.5.10 before 2.10.1
- **Fixed in:** 2.10.1 (Update to 2.10.1 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/buddyforms
- **Fix released:** 2026-10-03
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0582/

## Description

The BuddyForms plugin for WordPress is vulnerable to unauthorized file uploads via the upload_image_from_url AJAX action in all versions up to, and including, 2.10.0. This is due to a missing nonce check and a missing form-level permission check. The accepted file types were also taken from the request instead of the form field settings. This makes it possible for unauthenticated attackers to have the site download remote images and store them as attachments in the media library, regardless of form settings.

## References

- https://wpsec.com/vuln/WPSEC-2026-0582/
- https://plugins.svn.wordpress.org/buddyforms/tags/2.10.1/
- https://wordpress.org/plugins/buddyforms/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0582/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
