PT-2025-43845 · Themekraft+1 · Buddyforms

Published

2025-10-27

·

Updated

2025-10-27

·

CVE-2025-62973

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions BuddyForms versions prior to 2.9.1
Description Missing authorization allows accessing functionality not properly constrained by Access Control Lists (ACLs), which are mechanisms used to define which users or system processes are granted access to specific objects.
Recommendations Update to a version later than 2.9.0.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-62973

Affected Products

Buddyforms