Contact Form 7 Multi-Step Forms <= 4.7 - Unauthenticated Reflected Cross-Site Scripting via 'l10n_print_after' Form Field

Medium 6.1 CWE-79Fixed in 4.7.1
ID
WPSEC-2026-0691
Plugin
Webheadcoder Multi-Step Forms for Contact Form 7 (contact-form-7-multi-step-module)
Affected
all versions before 4.7.1
Remediation
Update to 4.7.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-10
Attack surface
Contact Form 7 Multi-Step Forms on WPSec AttackSurface
Fix released
Published

Description

The Webheadcoder Multi-Step Forms for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'l10n_print_after' form field in all versions up to, and including, 4.7. This is because form data saved between steps (in the cf7msm_posted_data cookie or the PHP session) is passed to wp_localize_script() without the reserved 'l10n_print_after' key being removed, and WordPress prints that key's value as raw JavaScript. This makes it possible for unauthenticated attackers to run arbitrary script in a victim's browser on pages that load the plugin's script, if they can trick the victim into submitting a crafted multi-step form request.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0