# Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Unauthenticated Missing Authorization to Arbitrary Post Modification

- **ID:** WPSEC-2026-0583
- **Plugin:** BuddyForms (`buddyforms`), https://wordpress.org/plugins/buddyforms/
- **Affected versions:** from 2.5.2 before 2.10.1
- **Fixed in:** 2.10.1 (Update to 2.10.1 or later.)
- **Severity:** High 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/buddyforms
- **Fix released:** 2026-10-03
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0583/

## Description

The BuddyForms plugin for WordPress is vulnerable to unauthorized modification of data in versions 2.5.2 up to, and including, 2.10.0. This is due to missing ownership and post type checks when a form submission targets an existing post: the post type check only ran for logged-in users and compared the post against a type sent in the request, and forms with public submission enabled, the default permission for new forms, granted edit rights to every submitter, including for updates. This makes it possible for unauthenticated attackers to overwrite the title, content, status and form field values of arbitrary posts and pages through a public form.

## References

- https://wpsec.com/vuln/WPSEC-2026-0583/
- https://plugins.svn.wordpress.org/buddyforms/tags/2.10.1/
- https://wordpress.org/plugins/buddyforms/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0583/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
