VYPR
Unrated severityNVD Advisory· Published May 17, 2024· Updated Apr 28, 2026

WordPress buddyforms plugin <= 2.8.8- Arbitrary File Read and SSRF vulnerability

CVE-2024-32830

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forgery, Relative Path Traversal.This issue affects BuddyForms: from n/a through 2.8.8.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.