Vulnerabilities > Mondula > Multi Step Form > 1.7.23

DATE CVE VULNERABILITY TITLE RISK
2025-01-16 CVE-2024-12427 Missing Authorization vulnerability in Mondula Multi Step Form
The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23.
network
low complexity
mondula CWE-862
5.3