Critical
Low
Medium
CVE-2025-9515
Overview
The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the import functionality in all versions up to, and including, 1.7.25. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arb...
Critical
Low
Medium
No items found.