Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2024-12427

Disclosure Date: January 16, 2025 (last updated January 16, 2025)
The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attackers to upload limited file types such as images.
Attacker Value
Unknown

CVE-2024-50428

Disclosure Date: October 29, 2024 (last updated October 30, 2024)
Missing Authorization vulnerability in Mondula GmbH Multi Step Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Multi Step Form: from n/a through 1.7.21.
0
Attacker Value
Unknown

CVE-2024-25905

Disclosure Date: February 21, 2024 (last updated February 21, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from n/a through 1.7.18.
0
Attacker Value
Unknown

CVE-2023-50832

Disclosure Date: December 21, 2023 (last updated December 30, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mondula GmbH Multi Step Form allows Stored XSS.This issue affects Multi Step Form: from n/a through 1.7.13.
Attacker Value
Unknown

CVE-2023-47758

Disclosure Date: November 22, 2023 (last updated November 28, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form plugin <= 1.7.11 versions.
Attacker Value
Unknown

CVE-2022-4196

Disclosure Date: January 09, 2023 (last updated October 08, 2023)
The Multi Step Form WordPress plugin before 1.7.8 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Attacker Value
Unknown

CVE-2018-14846

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
The Mondula Multi Step Form plugin before 1.2.8 for WordPress has multiple stored XSS via wp-admin/admin-ajax.php.
0
Attacker Value
Unknown

CVE-2018-14430

Disclosure Date: July 25, 2018 (last updated November 27, 2024)
The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_data [id][3], fw_data [id][4], or email field of the contact form, exploitable with an fw_send_email action to wp-admin/admin-ajax.php.
0