PT-2025-36352 · WordPress · Multi Step Form

Tmrswrr

·

Published

2025-09-06

·

Updated

2025-09-06

·

CVE-2025-9515

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Multi Step Form plugin for WordPress versions prior to 1.7.26
Description The Multi Step Form plugin for WordPress is susceptible to arbitrary file uploads due to a lack of file type validation during the import process. This allows authenticated attackers with Administrator-level access or higher to upload arbitrary files to the affected server, potentially leading to remote code execution.
Recommendations Update the Multi Step Form plugin to version 1.7.26 or later.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-9515

Affected Products

Multi Step Form