Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-12427
Disclosure Date: January 16, 2025 (last updated January 16, 2025)
The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attackers to upload limited file types such as images.
0
Attacker Value
Unknown
CVE-2024-50428
Disclosure Date: October 29, 2024 (last updated October 30, 2024)
Missing Authorization vulnerability in Mondula GmbH Multi Step Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Multi Step Form: from n/a through 1.7.21.
0
Attacker Value
Unknown
CVE-2024-25905
Disclosure Date: February 21, 2024 (last updated February 21, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from n/a through 1.7.18.
0
Attacker Value
Unknown
CVE-2023-50832
Disclosure Date: December 21, 2023 (last updated December 30, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mondula GmbH Multi Step Form allows Stored XSS.This issue affects Multi Step Form: from n/a through 1.7.13.
0
Attacker Value
Unknown
CVE-2023-47758
Disclosure Date: November 22, 2023 (last updated November 28, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form plugin <= 1.7.11 versions.
0
Attacker Value
Unknown
CVE-2022-4196
Disclosure Date: January 09, 2023 (last updated October 08, 2023)
The Multi Step Form WordPress plugin before 1.7.8 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0
Attacker Value
Unknown
CVE-2018-14846
Disclosure Date: December 20, 2018 (last updated November 27, 2024)
The Mondula Multi Step Form plugin before 1.2.8 for WordPress has multiple stored XSS via wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2018-14430
Disclosure Date: July 25, 2018 (last updated November 27, 2024)
The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_data [id][3], fw_data [id][4], or email field of the contact form, exploitable with an fw_send_email action to wp-admin/admin-ajax.php.
0