📦 Buddyforms

by Themekraft

🔍 What is Buddyforms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-26326

CRITICAL CVSS 9.8 Feb 23, 2023

The BuddyForms WordPress plugin before version 2.7.8 contains an unauthenticated insecure deserialization vulnerability. Attackers can exploit this without credentials to execute arbitrary PHP code on...

CVE-2024-32830

HIGH CVSS 8.6 May 17, 2024

This path traversal vulnerability in the BuddyForms WordPress plugin allows attackers to read arbitrary files and perform server-side request forgery (SSRF) attacks. It affects all BuddyForms installa...

CVE-2025-62973

MEDIUM CVSS 5.3 Oct 27, 2025

This CVE describes a missing authorization vulnerability in the BuddyForms WordPress plugin that allows attackers to access functionality not properly constrained by access controls. Users running Bud...

CVE-2024-12038

MEDIUM CVSS 6.4 Feb 22, 2025

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts via the 'buddyforms_nav' shortcode. The scripts are stored and execute whene...

CVE-2024-5149

MEDIUM CVSS 6.5 Jun 5, 2024

The BuddyForms WordPress plugin has an email verification bypass vulnerability due to insufficiently random activation codes. Unauthenticated attackers can bypass email verification requirements, pote...