CVE-2025-62973 Details
Description
Missing Authorization vulnerability in Themekraft BuddyForms buddyforms allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BuddyForms: from n/a through <= 2.9.0.
A missing authorization vulnerability has been identified in Themekraft BuddyForms plugin, specifically in versions through 2.9.0. This vulnerability allows users to access functionalities that are not properly restricted by Access Control Lists (ACLs), potentially leading to unauthorized actions or data exposure.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://patchstack.com/database/Wordpress/Plugin/buddyforms/vulnerability/wordpress-buddyforms-plugin-2-9-0-broken-access-control-vulnerability?_s_id=cve | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| themekraft buddyforms | <= 2.9.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jan 20, 2026 | CVE Modified | [email protected] |
| Nov 25, 2025 | Initial Analysis | [email protected] |
| Nov 13, 2025 | CVE Modified | [email protected] |
| Oct 27, 2025 | CVE Modified | CISA-ADP |
| Oct 27, 2025 | New CVE Received | [email protected] |