Medium severity5.3NVD Advisory· Published Jan 16, 2025· Updated Jun 17, 2026
CVE-2024-12427
CVE-2024-12427
Description
The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attackers to upload limited file types such as images.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:mondula:multi_step_form:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:mondula:multi_step_form:*:*:*:*:*:wordpress:*:*range: <1.7.24
- (no CPE)range: 0
<=1.7.23+ 1 more
- (no CPE)range: <=1.7.23
- (no CPE)
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/f0a31fee-ccc2-4c3b-b198-6cb750188113nvdThird Party Advisory
- plugins.trac.wordpress.org/browser/multi-step-form/tags/1.7.22/includes/lib/msf-shortcode.class.phpnvdProduct
- plugins.trac.wordpress.org/browser/multi-step-form/tags/1.7.22/includes/lib/msf-shortcode.class.phpnvdProduct
News mentions
0No linked articles in our index yet.