# Contact Form 7 Multi-Step Forms <= 4.7 - Unauthenticated Reflected Cross-Site Scripting via 'l10n_print_after' Form Field

- **ID:** WPSEC-2026-0691
- **Plugin:** Webheadcoder Multi-Step Forms for Contact Form 7 (`contact-form-7-multi-step-module`), https://wordpress.org/plugins/contact-form-7-multi-step-module/
- **Affected versions:** all versions before 4.7.1
- **Fixed in:** 4.7.1 (Update to 4.7.1 or later.)
- **Severity:** Medium 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/contact-form-7-multi-step-module
- **Fix released:** 2026-10-09
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0691/

## Description

The Webheadcoder Multi-Step Forms for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'l10n_print_after' form field in all versions up to, and including, 4.7. This is because form data saved between steps (in the cf7msm_posted_data cookie or the PHP session) is passed to wp_localize_script() without the reserved 'l10n_print_after' key being removed, and WordPress prints that key's value as raw JavaScript. This makes it possible for unauthenticated attackers to run arbitrary script in a victim's browser on pages that load the plugin's script, if they can trick the victim into submitting a crafted multi-step form request.

## References

- https://wpsec.com/vuln/WPSEC-2026-0691/
- https://plugins.svn.wordpress.org/contact-form-7-multi-step-module/tags/4.7.1/
- https://wordpress.org/plugins/contact-form-7-multi-step-module/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0691/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
