{
 "id": "WPSEC-2026-0584",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0584/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0584/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0584/index.md",
 "title": "Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.2 - Unauthenticated Missing Authorization to Form Configuration Export",
 "description": "The BuddyForms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check and missing nonce validation on the buddyforms_export_form() function in all versions up to, and including, 2.10.2. The function runs on the admin_init hook, which WordPress also fires for logged-out requests to admin-ajax.php and admin-post.php, and returned the stored configuration of any form. This makes it possible for unauthenticated attackers to export the full configuration of any BuddyForms form, including its fields, notification sender and recipient addresses, and the private key of a reCAPTCHA field if one is configured.",
 "plugin": {
  "slug": "buddyforms",
  "name": "Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms",
  "full_name": "BuddyForms",
  "wordpress_org": "https://wordpress.org/plugins/buddyforms/",
  "advisories_url": "https://wpsec.com/vuln/plugin/buddyforms/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/buddyforms"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-862"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "2.10.3",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 2.10.3"
  ]
 },
 "introduced_in": null,
 "fixed_in": "2.10.3",
 "remediation": "Update to 2.10.3 or later.",
 "fix_released": "2026-10-06T15:31:16+00:00",
 "published": "2026-10-07T19:47:10+00:00",
 "updated": "2026-10-07T18:51:23.307135+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0584/",
  "https://plugins.svn.wordpress.org/buddyforms/tags/2.10.3/",
  "https://wordpress.org/plugins/buddyforms/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/buddyforms",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-07"
 }
}