Vulnerabilities / Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms

Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms vulnerabilities

Advisories WPSec published for BuddyForms. Other sources may list more. Its attack surface: Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms on WPSec AttackSurface.

PublishedIDVulnerabilitySeverityFixed in
2026-10-07 WPSEC-2026-0586 Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.3 - Authenticated (Contributor+) Path Traversal to Local File Inclusion via List Submissions Block High 8.8 2.10.4
2026-10-07 WPSEC-2026-0585 Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.3 - Unauthenticated Missing Authorization to Arbitrary Taxonomy Term Disclosure via bf_load_taxonomy AJAX Action Medium 5.3 2.10.4
2026-10-07 WPSEC-2026-0584 Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.2 - Unauthenticated Missing Authorization to Form Configuration Export Medium 5.3 2.10.3
2026-10-07 WPSEC-2026-0583 Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Unauthenticated Missing Authorization to Arbitrary Post Modification High 7.5 2.10.1
2026-10-07 WPSEC-2026-0582 Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Unauthenticated Missing Authorization to Image Upload via upload_image_from_url AJAX Action Medium 5.3 2.10.1
2026-10-07 WPSEC-2026-0581 Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Unauthenticated Missing Authorization to Limited Attachment Deletion Medium 5.3 2.10.1
2026-10-07 WPSEC-2026-0580 Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Reflected Cross-Site Scripting via 'error_msg_*' Parameters Medium 6.1 2.10.1
2026-10-07 WPSEC-2026-0579 Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.10.0 - Unauthenticated Information Exposure via Failed Form Submissions Low 3.7 2.10.1

License: CC BY 4.0