
BuddyForms Advanced Custom Fields Security & Risk Analysis
wordpress.org/plugins/buddyforms-acfAdd BuddyForms frontend forms that map to field groups created with the Advanced Custom Fields plugin. Independent integration; ACF is not included.
Is BuddyForms Advanced Custom Fields Safe to Use in 2026?
Generally Safe
Score 100/100BuddyForms Advanced Custom Fields has a strong security track record. Known vulnerabilities have been patched promptly.
The buddyforms-acf plugin version 1.3.20 exhibits a mixed security posture. While the code demonstrates strong adherence to secure coding practices, such as 100% usage of prepared statements for SQL queries and a high rate of output escaping (94%), there are significant concerns. The presence of one AJAX handler without authentication checks represents a direct and exploitable attack vector, which is further amplified by the fact that this is the plugin's only entry point discovered in the static analysis. The plugin has a history of one known medium severity Cross-Site Scripting (XSS) vulnerability, last patched in August 2022. Although there are no currently unpatched vulnerabilities, this past issue highlights a potential area of weakness.
Overall, the plugin's strengths lie in its robust handling of database queries and output sanitization. However, the single unprotected AJAX endpoint is a critical flaw that could allow unauthorized users to trigger potentially harmful actions or inject malicious scripts. The vulnerability history, while resolved, serves as a reminder that XSS is a concern for this plugin. The lack of taint analysis results is noted, but the presence of an unprotected AJAX endpoint is a more immediate and quantifiable risk than theoretical taint flows.
Key Concerns
- Unprotected AJAX handler
- Past medium XSS vulnerability
BuddyForms Advanced Custom Fields Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
BuddyForms ACF <= 1.3.8 - Authenticated (Contributor+) Cross-Site Scripting
BuddyForms Advanced Custom Fields Code Analysis
Output Escaping
BuddyForms Advanced Custom Fields Attack Surface
AJAX Handlers 1
WordPress Hooks 38
Maintenance & Trust
BuddyForms Advanced Custom Fields Maintenance & Trust
Maintenance Signals
Community Trust
BuddyForms Advanced Custom Fields Alternatives
Post Submissions for Elementor Forms
post-submissions-for-elementor-forms
Allow users to submit WordPress posts directly from Elementor Forms. Easy setup, flexible, and developer-friendly.
LH Xprofile forms
lh-xprofile-forms
Decouple Xprofile forms from the profile and signup screens via a shortcode
Airy Frontend Forms
airy-frontend-forms
Create powerful frontend submission forms for ACF and SCF with complete control over fields, taxonomies, and user submissions.
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
FormsDB – Save Elementor Forms to Google Sheets & Post Type
sb-elementor-contact-form-db
Connect Elementor forms with Google Sheets to sync form entries, or save form submissions in any post type using Elementor Pro or Hello Plus forms.
BuddyForms Advanced Custom Fields Developer Profile
12 plugins · 5K total installs
How We Detect BuddyForms Advanced Custom Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddyforms-acf/assets/admin/js/form-builder.js/wp-content/plugins/buddyforms-acf/assets/admin/js/form-builder.jsbuddyforms-acf/assets/admin/js/form-builder.js?ver=advanced-custom-fields/assets/build/js/acf-field-group.js?ver=advanced-custom-fields/assets/build/js/acf-field-group.min.js?ver=HTML / DOM Fingerprints
Check the plugin dependenciesdata-iddata-repeater-fielddata-repeatdata-button-labeldata-add-rowdata-remove-row+16 moreBuddyFormsACFwpColorPickerL10n