Cross-Site Scripting
8 records40%First: 2022. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 20 vulnerability records associated with Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC), published between 2018 and 2025.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2018 | 1 | |
| 2019 | 1 | |
| 2022 | 3 | |
| 2023 | 3 | |
| 2024 | 8 | |
| 2025 | 4 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 10% |
| High | 6 | 30% |
| Medium | 12 | 60% |
First: 2022. Latest: 2025.
First: 2019. Latest: 2025.
First: 2023. Latest: 2025.
First: 2018. Latest: 2018.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
2.8.162.8.142.8.132.8.122.8.102.8.92.8.62.8.82.8.32.8.22.7.82.7.32.6.102.6.32.3.22.2.8Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.9.0 | BuddyForms <= 2.9.0 - Missing Authorization | October 19, 2025 | Not supplied | Medium |
*-2.8.17 | BuddyForms <= 2.8.17 - Authenticated (Contributor+) Local File Inclusion | April 4, 2025 | Not supplied | High |
*-2.8.15 | Frontend Content Forms for User Submissions (UGC) <= 2.8.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'buddyforms_nav' Shortcode | February 21, 2025 | 2.8.16 | Medium |
*-2.8.13 | Frontend Content Forms for User Submissions (UGC) <= 2.8.13 - Authenticated (Contributor+) Stored Cross-Site Scripting | January 30, 2025 | 2.8.14 | Medium |
*-2.8.12 | BuddyForms <= 2.8.12 - Authenticated (Editor+) Stored Cross-Site Scripting | September 30, 2024 | 2.8.13 | Medium |
*-2.8.11 | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.11 - Authenticated (Contributor+) Privilege Escalation | September 13, 2024 | 2.8.12 | High |
*-2.8.9 | BuddyForms <= 2.8.9 - Email Verification Bypass due to Insufficient Randomness | June 4, 2024 | 2.8.10 | Medium |
*-2.8.8 | BuddyForms <= 2.8.8 - Unauthenticated Arbitrary File Read and Server-Side Request Forgery | April 22, 2024 | 2.8.9 | Critical |
*-2.8.5 | BuddyForms <= 2.8.5 - Reflected Cross-Site Scripting via page | March 25, 2024 | 2.8.6 | Medium |
*-2.8.7 | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Upload | March 6, 2024 | 2.8.8 | High |
*-2.8.7 | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Deletion | March 6, 2024 | 2.8.8 | High |
*-2.8.7 | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization | March 6, 2024 | 2.8.8 | Medium |
*-2.8.2 | Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get | July 18, 2023 | 2.8.3 | Medium |
*-2.8.1 | Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | May 11, 2023 | 2.8.2 | Medium |
*-2.7.7 | BuddyForms <= 2.7.7 - PHAR Deserialization | February 20, 2023 | 2.7.8 | High |
*-2.7.2 | BuddyForms <= 2.7.2 - Authenticated (Contributor+) Stored Stored Cross-Site Scripting | October 27, 2022 | 2.7.3 | Medium |
*-2.6.9 | Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.6.9 - Cross-Site Scripting | June 26, 2022 | 2.6.10 | Medium |
[*, 2.6.3) | Freemius SDK <= 2.4.2 - Missing Authorization Checks | March 4, 2022 | 2.6.3 | Medium |
[*, 2.3.2) | Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update | February 25, 2019 | 2.3.2 | High |
*-2.2.7 | Post, Registration and Profile Form Builder – FrontEnd Editor BuddyForms – Easy WordPress Forms <= 2.2.7 - SQL Injection | November 9, 2018 | 2.2.8 | Critical |
Selected source records
Published: October 19, 2025
Published: April 4, 2025
Published: February 21, 2025
Published: January 30, 2025
Published: September 30, 2024
Published: September 13, 2024
Published: June 4, 2024
Published: April 22, 2024
Published: November 9, 2018
Published: April 22, 2024
Published: February 20, 2023
Published: February 25, 2019
Published: September 13, 2024
Published: April 4, 2025
Published: March 6, 2024
Published: March 6, 2024
Published: October 19, 2025
Published: April 4, 2025
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.