← WordPress Vulnerabilities
WordPress security by component

BuddyForms

BuddyForms is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Oct 27, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: buddyforms

CVE-2025-62973: BuddyForms: A security weakness

BuddyForms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedOct 27, 2025
Safe version guidanceSee mitigation notes
Safe version
Oct 27, 2025 CVE-2025-62973
BuddyForms: A security weakness
BuddyForms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Apr 04, 2025 CVE-2025-32151
BuddyForms: Filesystem traversal
BuddyForms is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVD8.8
Feb 22, 2025 CVE-2024-12038
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC): Cross-site scripting
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Oct 05, 2024 CVE-2024-47377
BuddyForms: Cross-site scripting
BuddyForms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD5.4
Sep 14, 2024 CVE-2024-8246
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC): Privilege escalation or authentication bypass
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) is affected by privilege escalation or authentication bypass. Exploitation requires at least contributor-level access. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Jun 05, 2024 CVE-2024-5149
BuddyForms: A security weakness
BuddyForms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD5.3
May 17, 2024 CVE-2024-32830
BuddyForms: Filesystem traversal
BuddyForms is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.6
NVD7.5
Mar 27, 2024 CVE-2024-30198
BuddyForms: Cross-site scripting
BuddyForms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.8
NVD6.1
Mar 13, 2024 CVE-2024-1158
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC): A security weakness
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Mar 07, 2024 CVE-2024-1170
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC): A security weakness
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.2
NVD8.2
Mar 07, 2024 CVE-2024-1169
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC): A security weakness
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Aug 25, 2023 CVE-2023-25981
Buddyforms: Cross-site scripting
Buddyforms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 16, 2023 CVE-2022-38971
Buddyforms: Cross-site scripting
Buddyforms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.7
NVD5.4
Feb 23, 2023 CVE-2023-26326
BuddyForms: Code execution
BuddyForms is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVD9.8
Aug 27, 2019 CVE-2018-21003
Buddyforms: SQL injection
Buddyforms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8