Contact Form 7 Multi-Step Forms <= 4.7 - Unauthenticated Reflected Cross-Site Scripting via 'l10n_print_after' Form Field
- ID
- WPSEC-2026-0691
- Plugin
- Webheadcoder Multi-Step Forms for Contact Form 7 (contact-form-7-multi-step-module)
- Affected
- all versions before 4.7.1
- Remediation
- Update to 4.7.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-10
- Attack surface
- Contact Form 7 Multi-Step Forms on WPSec AttackSurface
- Fix released
- Published
Description
The Webheadcoder Multi-Step Forms for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'l10n_print_after' form field in all versions up to, and including, 4.7. This is because form data saved between steps (in the cf7msm_posted_data cookie or the PHP session) is passed to wp_localize_script() without the reserved 'l10n_print_after' key being removed, and WordPress prints that key's value as raw JavaScript. This makes it possible for unauthenticated attackers to run arbitrary script in a victim's browser on pages that load the plugin's script, if they can trick the victim into submitting a crafted multi-step form request.
References
- https://wpsec.com/vuln/WPSEC-2026-0691/
- https://plugins.svn.wordpress.org/contact-form-7-multi-step-module/tags/4.7.1/
- https://wordpress.org/plugins/contact-form-7-multi-step-module/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS