CVE-2025-32151: WordPress BuddyForms Plugin <= 2.9.0 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themekraft BuddyForms buddyforms allows PHP Local File Inclusion.This issue affects BuddyForms: from n/a through <= 2.9.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32151?
CVE-2025-32151 is classified as a critical vulnerability due to its potential for remote file inclusion and exploitation.
How do I fix CVE-2025-32151?
To mitigate CVE-2025-32151, update BuddyForms to the latest version beyond 2.8.15 to rectify the local file inclusion vulnerability.
Which versions of BuddyForms are affected by CVE-2025-32151?
CVE-2025-32151 affects BuddyForms versions from n/a up to and including 2.8.15.
What type of vulnerability is CVE-2025-32151?
CVE-2025-32151 is an improper control of filename vulnerability leading to PHP local file inclusion.
Who is the vendor associated with CVE-2025-32151?
The vendor associated with CVE-2025-32151 is Sven Lehnert, the creator of BuddyForms.