plugin

Multi Step Form Vulnerabilities

18 known security issues reported for the Multi Step Form WordPress plugin. Most recent disclosed Sep 5, 2025.

1 high 8 medium

Running Multi Step Form on your site? Check whether your installed version is affected.

Scan your site free

Multi Step Form <= 1.7.25 - Authenticated (Admin+) Arbitrary File Upload

high

The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the import functionality in all versions up to, and including, 1.7.25. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the...

CVSS:
7.2
Affected:
up to 1.7.25
Fixed in:
1.7.26
Disclosed:
Sep 5, 2025

CVE-2025-9515 on NVD →

Multi Step Form [multi-step-form] < 1.7.24 (closed)

unknown

[en] The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attackers to upload limited file types such as images.

Affected:
up to 1.7.24
Fixed in:
1.7.24
Disclosed:
Jan 16, 2025

CVE-2024-12427 on NVD →

Multi Step Form <= 1.7.23 - Missing Authorization to Unauthenticated Limited File Upload

medium

The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attackers to upload limited file types such as images.

CVSS:
5.3
Affected:
up to 1.7.23
Fixed in:
1.7.24
Disclosed:
Jan 15, 2025

CVE-2024-12427 on NVD →

Multi Step Form [multi-step-form] < 1.7.22 (closed)

unknown

[en] Missing Authorization vulnerability in Mondula GmbH Multi Step Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Multi Step Form: from n/a through 1.7.21.

Affected:
up to 1.7.22
Fixed in:
1.7.22
Disclosed:
Oct 29, 2024

CVE-2024-50428 on NVD →

Multi Step Form <= 1.7.21 - Missing Authorization via fw_delete_files

medium

The Multi Step Form plugin for WordPress is vulnerable to unauthorized deletion of files due to a missing capability check on the fw_delete_files function in versions up to, and including, 1.7.21. This makes it possible for unauthenticated attackers to delete arbitrary attachments.

CVSS:
5.3
Affected:
up to 1.7.21
Fixed in:
1.7.22
Disclosed:
Oct 24, 2024

CVE-2024-50428 on NVD →

Multi Step Form [multi-step-form] < 1.7.19 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from n/a through 1.7.18.

Affected:
up to 1.7.19
Fixed in:
1.7.19
Disclosed:
Feb 21, 2024

CVE-2024-25905 on NVD →

Multi Step Form <= 1.7.18 - Cross-Site Request Forgery

medium

The Multi Step Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.18. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site...

CVSS:
4.3
Affected:
up to 1.7.18
Fixed in:
1.7.19
Disclosed:
Feb 12, 2024

CVE-2024-25905 on NVD →

Multi Step Form [multi-step-form] < 1.7.17 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mondula GmbH Multi Step Form allows Stored XSS.This issue affects Multi Step Form: from n/a through 1.7.13.

Affected:
up to 1.7.17
Fixed in:
1.7.17
Disclosed:
Dec 21, 2023

CVE-2023-50832 on NVD →

Multi Step Form <= 1.7.16 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Multi Step Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

CVSS:
4.4
Affected:
up to 1.7.16
Fixed in:
1.7.17
Disclosed:
Dec 19, 2023

CVE-2023-50832 on NVD →

Multi Step Form [multi-step-form] < 1.7.13 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form plugin <= 1.7.11 versions.

Affected:
up to 1.7.13
Fixed in:
1.7.13
Disclosed:
Nov 22, 2023

CVE-2023-47758 on NVD →

Multi Step Form <= 1.7.12 - Cross-Site Request Forgery

medium

The Multi Step Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.12. This is due to missing or incorrect nonce validation on the menu() function. This makes it possible for unauthenticated attackers to duplicate, edit, and delete forms via a forged request g...

CVSS:
4.3
Affected:
up to 1.7.12
Fixed in:
1.7.13
Disclosed:
Nov 13, 2023

CVE-2023-47758 on NVD →

Multi Step Form [multi-step-form] < 1.7.8 (closed)

unknown

[en] The Multi Step Form WordPress plugin before 1.7.8 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 1.7.8
Fixed in:
1.7.8
Disclosed:
Jan 9, 2023

CVE-2022-4196 on NVD →

Multi Step Form <= 1.7.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Multi Step Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its form fields in versions up to, and including, 1.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...

CVSS:
5.5
Affected:
up to 1.7.7
Fixed in:
1.7.8
Disclosed:
Dec 17, 2022

CVE-2022-4196 on NVD →

Multi Step Form [multi-step-form] < 1.2.8 (closed)

unknown

[en] The Mondula Multi Step Form plugin before 1.2.8 for WordPress has multiple stored XSS via wp-admin/admin-ajax.php.

Affected:
up to 1.2.8
Fixed in:
1.2.8
Disclosed:
Dec 20, 2018

CVE-2018-14846 on NVD →

Multi Step Form <= 1.2.5 - Stored Cross-Site Scripting

medium

The Mondula Multi Step Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fw_wizard_save’ action in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages th...

CVSS:
6.4
Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Jul 27, 2018

CVE-2018-14846 on NVD →

Multi Step Form [multi-step-form] < 1.2.6 (closed)

unknown

[en] The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_data [id][3], fw_data [id][4], or email field of the contact form, exploitable with an fw_send_email action to wp-admin/admin-ajax.php.

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Jul 25, 2018

CVE-2018-14430 on NVD →

Multi Step Form <= 1.2.5 - Reflected Cross-Site Scripting

medium

The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_data [id][3], fw_data [id][4], or email field of the contact form, exploitable with an fw_send_email action to wp-admin/admin-ajax.php.

CVSS:
6.1
Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Jul 20, 2018

CVE-2018-14430 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database