CVE-2025-9515
- EPSS 0.19%
- Veröffentlicht 06.09.2025 02:24:17
- Zuletzt bearbeitet 08.09.2025 16:25:38
The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the import functionality in all versions up to, and including, 1.7.25. This makes it possible for authenticated attackers, with A...
CVE-2024-12427
- EPSS 0.26%
- Veröffentlicht 16.01.2025 10:15:07
- Zuletzt bearbeitet 03.03.2025 17:42:59
The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated at...
CVE-2024-50428
- EPSS 0.23%
- Veröffentlicht 29.10.2024 22:15:05
- Zuletzt bearbeitet 25.02.2025 18:53:45
Missing Authorization vulnerability in Mondula GmbH Multi Step Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Multi Step Form: from n/a through 1.7.21.
CVE-2024-25905
- EPSS 0.05%
- Veröffentlicht 21.02.2024 07:15:57
- Zuletzt bearbeitet 23.04.2025 19:29:50
Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from n/a through 1.7.18.
CVE-2023-50832
- EPSS 0.12%
- Veröffentlicht 21.12.2023 18:15:08
- Zuletzt bearbeitet 21.11.2024 08:37:22
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mondula GmbH Multi Step Form allows Stored XSS.This issue affects Multi Step Form: from n/a through 1.7.13.
CVE-2023-47758
- EPSS 0.05%
- Veröffentlicht 22.11.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 08:30:45
Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form plugin <= 1.7.11 versions.
CVE-2022-4196
- EPSS 0.23%
- Veröffentlicht 09.01.2023 23:15:27
- Zuletzt bearbeitet 09.04.2025 14:15:26
The Multi Step Form WordPress plugin before 1.7.8 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is di...
CVE-2018-14846
- EPSS 0.22%
- Veröffentlicht 20.12.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:54
The Mondula Multi Step Form plugin before 1.2.8 for WordPress has multiple stored XSS via wp-admin/admin-ajax.php.
CVE-2018-14430
- EPSS 0.83%
- Veröffentlicht 25.07.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:02
The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_data [id][3], fw_data [id][4], or email field of the contact form, exploitable with an fw_send_email action to wp-admin/admin-ajax....