CVE-2025-62973: WordPress BuddyForms plugin <= 2.9.0 - Broken Access Control vulnerability
Published Oct 27, 2025
·Updated
Missing Authorization vulnerability in Themekraft BuddyForms buddyforms allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BuddyForms: from n/a through <= 2.9.0.
Affected Software
3 affected components
Themekraft BuddyForms<=2.9.0
WordPress BuddyForms<=2.9.0
Themekraft Buddyforms Wordpress<=2.9.0
Event History
Oct 27, 2025
CVE Published
via MITRE·01:34 AM
Data Sourced
via MITRE·01:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-62973?
CVE-2025-62973 is classified as a high-severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2025-62973?
To fix CVE-2025-62973, you should upgrade Themekraft BuddyForms to version 2.9.1 or later.
3
What are the affected versions of CVE-2025-62973?
CVE-2025-62973 affects all versions of Themekraft BuddyForms up to and including 2.9.0.
4
What type of vulnerability is CVE-2025-62973?
CVE-2025-62973 is a missing authorization vulnerability that allows unauthorized access to certain functionalities.
5
Who is impacted by CVE-2025-62973?
Users of Themekraft BuddyForms versions up to 2.9.0 are impacted by CVE-2025-62973.