Description
The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attackers to upload limited file types such as images.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50848 | The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attackers to upload limited file types such as images. |
References
History
Thu, 16 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Jan 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attackers to upload limited file types such as images. | |
| Title | Multi Step Form <= 1.7.23 - Missing Authorization to Unauthenticated Limited File Upload | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:32:17.199Z
Reserved: 2024-12-10T16:43:56.764Z
Link: CVE-2024-12427
Updated: 2025-01-16T14:23:59.877Z
Status : Received
Published: 2025-01-16T10:15:07.243
Modified: 2025-01-16T10:15:07.243
Link: CVE-2024-12427
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD