Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themekraft BuddyForms buddyforms allows PHP Local File Inclusion.This issue affects BuddyForms: from n/a through 2.10.2.
Published: 2025-04-04
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Local File Inclusion
Action: Immediate Patch
AI Analysis

Impact

The vulnerability results from improper control of filenames passed to PHP’s include/require statements within the BuddyForms plugin (CWE‑98). User‑supplied file names are used without adequate validation, allowing an attacker to have the plugin include arbitrary local files. Depending on the content of the included file, this can expose sensitive data or enable execution of malicious PHP code, effectively turning the LFI into a remote code execution vector.

Affected Systems

Themekraft BuddyForms plugin used in WordPress installations, all versions up to and including 2.10.2, are affected. The issue applies regardless of other plugins or the WordPress core version.

Risk and Exploitability

CVSS score of 7.5 designates high severity, while an EPSS score of less than 1% indicates exploitation is currently rare but still possible. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a public‑facing form or request that allows the attacker to specify a filename, though the precise input mechanism is not detailed in the description. The flaw is local, requiring some level of access to the WordPress installation, such as interacting with the plugin’s features.

Generated by OpenCVE AI on October 7, 2026 at 09:56 UTC.

Remediation

Vendor Solution

Update the WordPress BuddyForms plugin to the latest available version (at least 2.10.4).


OpenCVE Recommended Actions

  • Upgrade BuddyForms plugin to version 2.10.4 or later.
  • If an upgrade cannot be performed immediately, disable or remove the plugin’s feature that accepts user‑provided filenames until an official fix is released.
  • Configure PHP to limit directory access for the plugin, for example by enabling open_basedir or disabling allow_url_include, so that only approved directories can be read by the plugin.

Generated by OpenCVE AI on October 7, 2026 at 09:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9854 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Sven Lehnert BuddyForms allows PHP Local File Inclusion. This issue affects BuddyForms: from n/a through 2.8.15.
History

Wed, 07 Oct 2026 08:30:00 +0000


Wed, 07 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themekraft BuddyForms buddyforms allows PHP Local File Inclusion.This issue affects BuddyForms: from n/a through <= 2.9.0. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themekraft BuddyForms buddyforms allows PHP Local File Inclusion.This issue affects BuddyForms: from n/a through 2.10.2.
Title WordPress BuddyForms Plugin <= 2.9.0 - Local File Inclusion vulnerability WordPress BuddyForms plugin <= 2.10.2 - Local File Inclusion vulnerability
References

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Sven Lehnert BuddyForms allows PHP Local File Inclusion. This issue affects BuddyForms: from n/a through 2.8.15. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themekraft BuddyForms buddyforms allows PHP Local File Inclusion.This issue affects BuddyForms: from n/a through <= 2.9.0.
Title WordPress BuddyForms Plugin <= 2.8.15 - Local File Inclusion vulnerability WordPress BuddyForms Plugin <= 2.9.0 - Local File Inclusion vulnerability
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 26 Nov 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Themekraft
Themekraft buddyforms
CPEs cpe:2.3:a:themekraft:buddyforms:*:*:*:*:*:wordpress:*:*
Vendors & Products Themekraft
Themekraft buddyforms

Fri, 04 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Sven Lehnert BuddyForms allows PHP Local File Inclusion. This issue affects BuddyForms: from n/a through 2.8.15.
Title WordPress BuddyForms Plugin <= 2.8.15 - Local File Inclusion vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Themekraft Buddyforms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-07T07:43:17.055Z

Reserved: 2025-04-04T10:00:50.063Z

Link: CVE-2025-32151

cve-icon Vulnrichment

Updated: 2025-04-04T19:53:34.522Z

cve-icon NVD

Status : Modified

Published: 2025-04-04T16:15:23.370

Modified: 2026-10-07T08:16:55.577

Link: CVE-2025-32151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T10:00:07Z

Weaknesses
  • CWE-98

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')