The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.7.23. This makes it possible for unauthenticated attackers to upload limited file types such as images.
References
Configurations
No configuration.
History
16 Jan 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-16 10:15
Updated : 2025-01-16 10:15
NVD link : CVE-2024-12427
Mitre link : CVE-2024-12427
CVE.ORG link : CVE-2024-12427
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization