Impact
The Multi Step Form plugin for WordPress contains a flaw in its import functionality that fails to validate the type of uploaded files. An attacker who has Administrator privileges can exploit this issue to upload any file to the site’s server, including scripts or executables that, if placed in a web-accessible directory, could be run by the web server. The absence of file‑type checks means that the attack does not rely on other weaknesses, placing the core vulnerability in the category of unrestricted upload, which can lead to remote code execution.
Affected Systems
This vulnerability affects installations of the Multi Step Form plugin created by mondula2016. All releases up to and including version 1.7.25 are impacted. The issue is specific to WordPress sites that rely on this plugin and does not extend to other WordPress components or third‑party plugins.
Risk and Exploitability
The CVSS score of 7.2 places the vulnerability in the high category, while the EPSS score of <1% indicates a low probability of exploitation at present. The plugin is not listed in CISA’s KEV catalog. Attackers must first obtain Administrator level access to the WordPress site, which limits the threat to sites with poor internal controls or compromised admin credentials. Once satisfied, an attacker can use the import feature to drop malicious files, potentially enabling execution of arbitrary code or further compromise of the server.
OpenCVE Enrichment
EUVD