
BuddyForms Advanced Custom Fields Security & Risk Analysis
wordpress.org/plugins/buddyforms-acfAdd BuddyForms frontend forms that map to field groups created with the Advanced Custom Fields plugin. Independent integration; ACF is not included.
Is BuddyForms Advanced Custom Fields Safe to Use in 2026?
Generally Safe
Score 100/100BuddyForms Advanced Custom Fields has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The buddyforms-acf plugin version 1.3.20 exhibits a mixed security posture. While the code demonstrates strong adherence to secure coding practices, such as 100% usage of prepared statements for SQL queries and a high rate of output escaping (94%), there are significant concerns. The presence of one AJAX handler without authentication checks represents a direct and exploitable attack vector, which is further amplified by the fact that this is the plugin's only entry point discovered in the static analysis. The plugin has a history of one known medium severity Cross-Site Scripting (XSS) vulnerability, last patched in August 2022. Although there are no currently unpatched vulnerabilities, this past issue highlights a potential area of weakness.
Overall, the plugin's strengths lie in its robust handling of database queries and output sanitization. However, the single unprotected AJAX endpoint is a critical flaw that could allow unauthorized users to trigger potentially harmful actions or inject malicious scripts. The vulnerability history, while resolved, serves as a reminder that XSS is a concern for this plugin. The lack of taint analysis results is noted, but the presence of an unprotected AJAX endpoint is a more immediate and quantifiable risk than theoretical taint flows.
Key Concerns
- Unprotected AJAX handler
- Past medium XSS vulnerability
BuddyForms Advanced Custom Fields Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
BuddyForms ACF <= 1.3.8 - Authenticated (Contributor+) Cross-Site Scripting
BuddyForms Advanced Custom Fields Release Timeline
BuddyForms Advanced Custom Fields Code Analysis
Output Escaping
BuddyForms Advanced Custom Fields Attack Surface
AJAX Handlers 1
WordPress Hooks 38
Maintenance & Trust
BuddyForms Advanced Custom Fields Maintenance & Trust
Maintenance Signals
Community Trust
BuddyForms Advanced Custom Fields Alternatives
Post Submissions for Elementor Forms
post-submissions-for-elementor-forms
Allow users to submit WordPress posts directly from Elementor Forms. Easy setup, flexible, and developer-friendly.
Airy Frontend Forms
airy-frontend-forms
Create powerful frontend submission forms for ACF and SCF with complete control over fields, taxonomies, and user submissions.
LH Xprofile forms
lh-xprofile-forms
Decouple Xprofile forms from the profile and signup screens via a shortcode
EHx Members
ehx-members
The EHx Members plugin is a powerful tool designed to simplify and streamline the user registration process on your WordPress site.
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
BuddyForms Advanced Custom Fields Developer Profile
12 plugins · 5K total installs
How We Detect BuddyForms Advanced Custom Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buddyforms-acf/assets/admin/js/form-builder.js/wp-content/plugins/buddyforms-acf/assets/admin/js/form-builder.jsbuddyforms-acf/assets/admin/js/form-builder.js?ver=advanced-custom-fields/assets/build/js/acf-field-group.js?ver=advanced-custom-fields/assets/build/js/acf-field-group.min.js?ver=HTML / DOM Fingerprints
Check the plugin dependenciesdata-iddata-repeater-fielddata-repeatdata-button-labeldata-add-rowdata-remove-row+16 moreBuddyFormsACFwpColorPickerL10n