CVE-2024-12427
16.01.2025, 10:15
The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attackers to upload limited file types such as images.Enginsight
Vendor | Product | Version |
---|---|---|
mondula | multi_step_form | 𝑥 < 1.7.24 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References