Executive brief
BuddyForms is a popular WordPress plugin used to create and manage forms on websites. An unauthenticated broken access control vulnerability allows visitors without proper permissions to access pages and perform actions they should not be allowed to, such as viewing other users' form data or sensitive information. This could lead to exposure of private user data and compromise of site integrity.
Technical details
The vulnerability is a broken access control issue in BuddyForms plugin versions 2.9.0 and earlier. The flaw allows unauthenticated attackers to bypass authorization checks and access restricted functionality without requiring authentication or proper privileges. Attack vector is network-based with no authentication required. An attacker can exploit this to view other users' data or perform unauthorized actions. No official patch is currently available as of the publication date.
Affected products
- BuddyForms BuddyForms <=2.9.0
Timeline
- 2026-09-10: disclosed
- 2026-04-26: other: Reported by Peng Zhou