The BuddyForms plugin for WordPress has a security issue in versions up to and including 2.8.17. This can allow attackers with certain levels of access to include and run their own files on the server, potentially allowing them to access private information or execute harmful code.