WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)

BuddyForms is a versatile plugin that allows the creation of post forms, registration forms, profile forms, content forms, and supports file uploads.

17Reported vulnerabilities
9.8Highest CVSS score
2.9.0Latest version
900+Active installs

What to do now

Update Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) to 2.8.16 or later. 15 of these have a fixed version available. Updating resolves them.

Plugin last updated: June 4, 2025 / Tested up to WordPress: 6.8.8 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-26326 Critical 9.8 3.8% Before 2.7.8 2.7.8 February 23, 2023
CVE-2018-21003 Critical 9.8 1.8% Before 2.2.8 2.2.8 August 27, 2019
CVE-2024-32830 Critical 9.3 0.6% 2.8.8 and earlier 2.8.9 April 22, 2024
CVE-2025-32151 High 8.8 1.0% 2.8.17 and earlier April 4, 2025
CVE-2024-8246 High 8.8 0.4% Before 2.8.12 2.8.12 September 14, 2024
CVE-2024-1170 High 8.2 0.7% Before 2.8.8 2.8.8 March 7, 2024
CVE-2024-1169 High 7.5 0.6% Before 2.8.8 2.8.8 March 7, 2024
CVE-2023-25981 Medium 6.4 0.4% 2.8.1 and earlier 2.8.2 May 11, 2023
CVE-2022-38971 Medium 6.4 0.4% 2.7.2 and earlier 2.7.3 October 27, 2022
CVE-2024-12037 Medium 6.4 0.2% 0 to 2.8.13 (inclusive) 2.8.14 January 31, 2025
CVE-2024-30198 Medium 6.1 0.3% 2.8.5 and earlier 2.8.6 March 25, 2024
WF-ba5d1bd4-da0d-43f4-b28f-4a4a2702b3b0 Medium 6.1 2.6.9 and earlier 2.6.10 June 26, 2022
CVE-2025-62973 Medium 5.3 0.2% 2.9.0 and earlier October 19, 2025
CVE-2024-12038 Medium 5.4 0.2% Before 2.8.16 2.8.16 February 22, 2025
CVE-2024-5149 Medium 5.3 0.4% 2.8.9 and earlier 2.8.10 June 5, 2024
CVE-2024-47377 Medium 4.4 0.3% 2.8.12 and earlier 2.8.13 September 30, 2024
CVE-2024-1158 Medium 4.3 0.5% Before 2.8.8 2.8.8 March 13, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.