Known vulnerabilities in the Buddyforms plugin
7 security advisories have been published for the Buddyforms plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Buddyforms - Cross-Site Scripting (XSS) (CVE-2024-12038) MEDIUM
- Buddyforms - Privilege Escalation (CVE-2024-8246) HIGH
- Buddyforms - Security Vulnerability (CVE-2024-5149) MEDIUM
- Buddyforms - Broken Access Control (CVE-2024-1158) MEDIUM
- Buddyforms - Broken Access Control (CVE-2024-1170) HIGH
- Buddyforms - Broken Access Control (CVE-2024-1169) HIGH
- Buddyforms - PHP Object Injection (CVE-2023-26326) CRITICAL