CVE-2025-62973
Executive Summary
CVE-2025-62973 is a missing authorization flaw in Themekraft BuddyForms (WordPress plugin) that allows attackers to invoke restricted functions without proper ACL checks. Affected versions up to 2.10.2. Exploitation could lead to unauthorized data access, modification, or execution of privileged actions. No current CISA KEV listing.
Authoritative CVE Metadata - CVSS Base Score: 5.3 (MEDIUM) - Published: 2025-10-27T02:15:57.890 - Last Modified: 2026-10-06T12:16:46.073
Original Description: Missing Authorization vulnerability in Themekraft BuddyForms buddyforms allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BuddyForms: from n/a through 2.10.2.
"Most folks are about as happy as they make up their minds to be."
— Abraham Lincoln
Source: NVD