Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.2 - Unauthenticated Missing Authorization to Form Configuration Export

Medium 5.3 CWE-862Fixed in 2.10.3
ID
WPSEC-2026-0584
Plugin
BuddyForms (buddyforms)
Affected
all versions before 2.10.3
Remediation
Update to 2.10.3 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms on WPSec AttackSurface
Fix released
Published

Description

The BuddyForms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check and missing nonce validation on the buddyforms_export_form() function in all versions up to, and including, 2.10.2. The function runs on the admin_init hook, which WordPress also fires for logged-out requests to admin-ajax.php and admin-post.php, and returned the stored configuration of any form. This makes it possible for unauthenticated attackers to export the full configuration of any BuddyForms form, including its fields, notification sender and recipient addresses, and the private key of a reCAPTCHA field if one is configured.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0