CVE-2024-12427

MEDIUM

Multi Step Form <= 1.7.23 - Unauthenticated Limited File Upload via fw_upload_file AJAX Action

Title source: llm
STIX 2.1

Description

The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attackers to upload limited file types such as images.

Scores

CVSS v3 5.3
EPSS 0.0039
EPSS Percentile 30.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
mondula/multi_step_form < 1.7.24
mondula2016/Multi Step Form < 1.7.23
Published Jan 16, 2025
Tracked Since Feb 18, 2026