Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.2 - Unauthenticated Missing Authorization to Form Configuration Export
- ID
- WPSEC-2026-0584
- Plugin
- BuddyForms (buddyforms)
- Affected
- all versions before 2.10.3
- Remediation
- Update to 2.10.3 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
- Attack surface
- Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms on WPSec AttackSurface
- Fix released
- Published
Description
The BuddyForms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check and missing nonce validation on the buddyforms_export_form() function in all versions up to, and including, 2.10.2. The function runs on the admin_init hook, which WordPress also fires for logged-out requests to admin-ajax.php and admin-post.php, and returned the stored configuration of any form. This makes it possible for unauthenticated attackers to export the full configuration of any BuddyForms form, including its fields, notification sender and recipient addresses, and the private key of a reCAPTCHA field if one is configured.
References
- https://wpsec.com/vuln/WPSEC-2026-0584/
- https://plugins.svn.wordpress.org/buddyforms/tags/2.10.3/
- https://wordpress.org/plugins/buddyforms/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS