Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Unauthenticated Missing Authorization to Arbitrary Post Modification

High 7.5 CWE-862Fixed in 2.10.1
ID
WPSEC-2026-0583
Plugin
BuddyForms (buddyforms)
Affected
from 2.5.2 before 2.10.1
Remediation
Update to 2.10.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms on WPSec AttackSurface
Fix released
Published

Description

The BuddyForms plugin for WordPress is vulnerable to unauthorized modification of data in versions 2.5.2 up to, and including, 2.10.0. This is due to missing ownership and post type checks when a form submission targets an existing post: the post type check only ran for logged-in users and compared the post against a type sent in the request, and forms with public submission enabled, the default permission for new forms, granted edit rights to every submitter, including for updates. This makes it possible for unauthenticated attackers to overwrite the title, content, status and form field values of arbitrary posts and pages through a public form.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0