Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Unauthenticated Missing Authorization to Arbitrary Post Modification
- ID
- WPSEC-2026-0583
- Plugin
- BuddyForms (buddyforms)
- Affected
- from 2.5.2 before 2.10.1
- Remediation
- Update to 2.10.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
- Attack surface
- Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms on WPSec AttackSurface
- Fix released
- Published
Description
The BuddyForms plugin for WordPress is vulnerable to unauthorized modification of data in versions 2.5.2 up to, and including, 2.10.0. This is due to missing ownership and post type checks when a form submission targets an existing post: the post type check only ran for logged-in users and compared the post against a type sent in the request, and forms with public submission enabled, the default permission for new forms, granted edit rights to every submitter, including for updates. This makes it possible for unauthenticated attackers to overwrite the title, content, status and form field values of arbitrary posts and pages through a public form.
References
- https://wpsec.com/vuln/WPSEC-2026-0583/
- https://plugins.svn.wordpress.org/buddyforms/tags/2.10.1/
- https://wordpress.org/plugins/buddyforms/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS