CVE-2025-62973: WordPress BuddyForms plugin <= 2.10.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in Themekraft BuddyForms buddyforms allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BuddyForms: from n/a through 2.10.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/buddyformsto a version that resolves this vulnerability.Fixed in 2.10.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62973?
CVE-2025-62973 is classified as a high-severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-62973?
To fix CVE-2025-62973, you should upgrade Themekraft BuddyForms to version 2.9.1 or later.
What are the affected versions of CVE-2025-62973?
CVE-2025-62973 affects all versions of Themekraft BuddyForms up to and including 2.9.0.
What type of vulnerability is CVE-2025-62973?
CVE-2025-62973 is a missing authorization vulnerability that allows unauthorized access to certain functionalities.
Who is impacted by CVE-2025-62973?
Users of Themekraft BuddyForms versions up to 2.9.0 are impacted by CVE-2025-62973.