Pricing
Case studies
Login
Start trial
BuddyForms
Themekraft
Developer
2.9.0
Latest version
1,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
2 present
17 patched
11 Mitigation rules
Broken Access Control vulnerability
<= 2.9.0
19/10/2025
Local File Inclusion vulnerability
<= 2.9.0
04/04/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via 'buddyforms_nav' Shortcode vulnerability
<= 2.8.15
21/02/2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 2.8.13
31/01/2025
Cross Site Scripting (XSS) vulnerability
<= 2.8.12
30/09/2024
Authenticated (Contributor+) Privilege Escalation vulnerability
<= 2.8.11
16/09/2024
Email Verification Bypass due to Insufficient Randomness vulnerability
<= 2.8.9
05/06/2024
WordPress buddyforms plugin <= 2.8.8- Arbitrary File Read and SSRF vulnerability
<= 2.8.8
22/04/2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 2.8.5
25/03/2024
Missing Authorization to Unauthenticated Media Deletion vulnerability
<= 2.8.7
07/03/2024
Missing Authorization vulnerability
<= 2.8.7
07/03/2024
Missing Authorization to Unauthenticated Media Upload vulnerability
<= 2.8.7
07/03/2024
Reflected Cross Site Scripting (XSS) vulnerability
< 2.8.3
18/07/2023
Cross Site Scripting (XSS) vulnerability
<= 2.8.1
12/05/2023
PHAR Deserialization vulnerability
<= 2.7.7
21/02/2023
Auth. Stored Cross-Site Scripting (XSS) vulnerability
<= 2.7.5
27/10/2022
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
<= 2.6.2
28/02/2022
Sensitive Information Disclosure vulnerability
<= 2.6.2
28/02/2022
Authenticated Option Update vulnerability (Fremius Library security issue)
<= 2.3.1
05/03/2019