{
 "id": "WPSEC-2026-0583",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0583/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0583/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0583/index.md",
 "title": "Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Unauthenticated Missing Authorization to Arbitrary Post Modification",
 "description": "The BuddyForms plugin for WordPress is vulnerable to unauthorized modification of data in versions 2.5.2 up to, and including, 2.10.0. This is due to missing ownership and post type checks when a form submission targets an existing post: the post type check only ran for logged-in users and compared the post against a type sent in the request, and forms with public submission enabled, the default permission for new forms, granted edit rights to every submitter, including for updates. This makes it possible for unauthenticated attackers to overwrite the title, content, status and form field values of arbitrary posts and pages through a public form.",
 "plugin": {
  "slug": "buddyforms",
  "name": "Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms",
  "full_name": "BuddyForms",
  "wordpress_org": "https://wordpress.org/plugins/buddyforms/",
  "advisories_url": "https://wpsec.com/vuln/plugin/buddyforms/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/buddyforms"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-862"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.5,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.5.2",
    "from_inclusive": true,
    "to": "2.10.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.5.2 before 2.10.1"
  ]
 },
 "introduced_in": "2.5.2",
 "fixed_in": "2.10.1",
 "remediation": "Update to 2.10.1 or later.",
 "fix_released": "2026-10-03T21:02:24+00:00",
 "published": "2026-10-07T19:47:10+00:00",
 "updated": "2026-10-07T18:51:22.064072+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0583/",
  "https://plugins.svn.wordpress.org/buddyforms/tags/2.10.1/",
  "https://wordpress.org/plugins/buddyforms/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/buddyforms",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-07"
 }
}