Multi Step Form <= 1.7.25 - Authenticated (Admin+) Arbitrary File Upload
high
The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the import functionality in all versions up to, and including, 1.7.25. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the...
- CVSS:
- 7.2
- Affected:
- up to 1.7.25
- Fixed in:
- 1.7.26
- Disclosed:
- Sep 5, 2025
CVE-2025-9515 on NVD →
Multi Step Form [multi-step-form] < 1.7.24 (closed)
unknown
[en] The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attackers to upload limited file types such as images.
- Affected:
- up to 1.7.24
- Fixed in:
- 1.7.24
- Disclosed:
- Jan 16, 2025
CVE-2024-12427 on NVD →
Multi Step Form <= 1.7.23 - Missing Authorization to Unauthenticated Limited File Upload
medium
The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attackers to upload limited file types such as images.
- CVSS:
- 5.3
- Affected:
- up to 1.7.23
- Fixed in:
- 1.7.24
- Disclosed:
- Jan 15, 2025
CVE-2024-12427 on NVD →
Multi Step Form [multi-step-form] < 1.7.22 (closed)
unknown
[en] Missing Authorization vulnerability in Mondula GmbH Multi Step Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Multi Step Form: from n/a through 1.7.21.
- Affected:
- up to 1.7.22
- Fixed in:
- 1.7.22
- Disclosed:
- Oct 29, 2024
CVE-2024-50428 on NVD →
Multi Step Form <= 1.7.21 - Missing Authorization via fw_delete_files
medium
The Multi Step Form plugin for WordPress is vulnerable to unauthorized deletion of files due to a missing capability check on the fw_delete_files function in versions up to, and including, 1.7.21. This makes it possible for unauthenticated attackers to delete arbitrary attachments.
- CVSS:
- 5.3
- Affected:
- up to 1.7.21
- Fixed in:
- 1.7.22
- Disclosed:
- Oct 24, 2024
CVE-2024-50428 on NVD →
Multi Step Form [multi-step-form] < 1.7.19 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from n/a through 1.7.18.
- Affected:
- up to 1.7.19
- Fixed in:
- 1.7.19
- Disclosed:
- Feb 21, 2024
CVE-2024-25905 on NVD →
Multi Step Form <= 1.7.18 - Cross-Site Request Forgery
medium
The Multi Step Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.18. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site...
- CVSS:
- 4.3
- Affected:
- up to 1.7.18
- Fixed in:
- 1.7.19
- Disclosed:
- Feb 12, 2024
CVE-2024-25905 on NVD →
Multi Step Form [multi-step-form] < 1.7.17 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mondula GmbH Multi Step Form allows Stored XSS.This issue affects Multi Step Form: from n/a through 1.7.13.
- Affected:
- up to 1.7.17
- Fixed in:
- 1.7.17
- Disclosed:
- Dec 21, 2023
CVE-2023-50832 on NVD →
Multi Step Form <= 1.7.16 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Multi Step Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...
- CVSS:
- 4.4
- Affected:
- up to 1.7.16
- Fixed in:
- 1.7.17
- Disclosed:
- Dec 19, 2023
CVE-2023-50832 on NVD →
Multi Step Form [multi-step-form] < 1.7.13 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form plugin <= 1.7.11 versions.
- Affected:
- up to 1.7.13
- Fixed in:
- 1.7.13
- Disclosed:
- Nov 22, 2023
CVE-2023-47758 on NVD →
Multi Step Form <= 1.7.12 - Cross-Site Request Forgery
medium
The Multi Step Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.12. This is due to missing or incorrect nonce validation on the menu() function. This makes it possible for unauthenticated attackers to duplicate, edit, and delete forms via a forged request g...
- CVSS:
- 4.3
- Affected:
- up to 1.7.12
- Fixed in:
- 1.7.13
- Disclosed:
- Nov 13, 2023
CVE-2023-47758 on NVD →
Multi Step Form [multi-step-form] < 1.7.8 (closed)
unknown
[en] The Multi Step Form WordPress plugin before 1.7.8 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.8
- Disclosed:
- Jan 9, 2023
CVE-2022-4196 on NVD →
Multi Step Form <= 1.7.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Multi Step Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its form fields in versions up to, and including, 1.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- CVSS:
- 5.5
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.8
- Disclosed:
- Dec 17, 2022
CVE-2022-4196 on NVD →
Multi Step Form [multi-step-form] < 1.2.8 (closed)
unknown
[en] The Mondula Multi Step Form plugin before 1.2.8 for WordPress has multiple stored XSS via wp-admin/admin-ajax.php.
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.8
- Disclosed:
- Dec 20, 2018
CVE-2018-14846 on NVD →
Multi Step Form <= 1.2.5 - Stored Cross-Site Scripting
medium
The Mondula Multi Step Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fw_wizard_save’ action in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages th...
- CVSS:
- 6.4
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Jul 27, 2018
CVE-2018-14846 on NVD →
Multi Step Form [multi-step-form] < 1.2.6 (closed)
unknown
[en] The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_data [id][3], fw_data [id][4], or email field of the contact form, exploitable with an fw_send_email action to wp-admin/admin-ajax.php.
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Jul 25, 2018
CVE-2018-14430 on NVD →
Multi Step Form <= 1.2.5 - Reflected Cross-Site Scripting
medium
The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_data [id][3], fw_data [id][4], or email field of the contact form, exploitable with an fw_send_email action to wp-admin/admin-ajax.php.
- CVSS:
- 6.1
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Jul 20, 2018
CVE-2018-14430 on NVD →
Multi Step Form [multi-step-form] < 1.7.26
unknown
- Affected:
- up to 1.7.26
- Fixed in:
- 1.7.26
CVE-2025-9515 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database