# Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.2 - Unauthenticated Missing Authorization to Form Configuration Export

- **ID:** WPSEC-2026-0584
- **Plugin:** BuddyForms (`buddyforms`), https://wordpress.org/plugins/buddyforms/
- **Affected versions:** all versions before 2.10.3
- **Fixed in:** 2.10.3 (Update to 2.10.3 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/buddyforms
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0584/

## Description

The BuddyForms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check and missing nonce validation on the buddyforms_export_form() function in all versions up to, and including, 2.10.2. The function runs on the admin_init hook, which WordPress also fires for logged-out requests to admin-ajax.php and admin-post.php, and returned the stored configuration of any form. This makes it possible for unauthenticated attackers to export the full configuration of any BuddyForms form, including its fields, notification sender and recipient addresses, and the private key of a reCAPTCHA field if one is configured.

## References

- https://wpsec.com/vuln/WPSEC-2026-0584/
- https://plugins.svn.wordpress.org/buddyforms/tags/2.10.3/
- https://wordpress.org/plugins/buddyforms/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0584/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
