CVE-2025-62973
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)
Minimum safe version
2.8.16
Update to 2.8.16 or later to address 26 fixable vulnerabilities
WordPress BuddyForms Plugin <= 2.9.0 - Local File Inclusion vulnerability
CVE-2024-12038
CVE-2024-12037
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-47377
WordPress BuddyForms Plugin <= 2.8.11 is vulnerable to Privilege Escalation
CVE-2024-5149
CVE-2024-32830
CVE-2024-30198
CVE-2024-1158
CVE-2024-1169
CVE-2024-1170
WordPress BuddyForms Plugin < 2.8.3 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-25981
Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WordPress BuddyForms Plugin <= 2.7.7 is vulnerable to PHP Object Injection
CVE-2023-26326
BuddyForms <= 2.7.7 - PHAR Deserialization
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.6.9 - Cross-Site Scripting
CVE-2022-38971
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
WordPress BuddyForms plugin <= 2.3.1 - Authenticated Option Update vulnerability (Fremius Library security issue)
WordPress BuddyForms plugin <= 2.6.2 - Sensitive Information Disclosure vulnerability
WordPress BuddyForms plugin <= 2.6.2 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2018-21003