High 7.2
2025-09-06< 1.7.26
Multi Step Form <= 1.7.25 - Authenticated (Admin+) Arbitrary File Upload
Minimum safe version
1.7.26
Update to 1.7.26 or later to address 9 fixable vulnerabilities
Multi Step Form <= 1.7.25 - Authenticated (Admin+) Arbitrary File Upload
CVE-2024-12427
CVE-2024-50428
CVE-2024-25905
WordPress Multi Step Form Plugin <= 1.7.13 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-47758
CVE-2022-4196
WordPress Multi Step Form plugin <= 1.2.5 - Multiple Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerabilities
CVE-2018-14846