PLUGIN SECURITY
Is Contact Form 7 Multi Step Module safe?
Adds multi-page, multi-step forms to Contact Form 7.
What this plugin does
- Slug:
contact-form-7-multi-step-module - Author: webheadcoder
- 50000+ active installs
- 84/100 rating (49 reviews on wordpress.org)
- 888355 all-time downloads
- On WordPress.org since 2013-04-15
contact form 7form persistencemulti page formmultistep form
Maintenance status
- Latest known version: 4.6.2
- Last updated: 2026-08-17 1:51am GMT
- Tested up to WordPress: 7.1
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
2 known CVEs on file for Contact Form 7 Multi Step Module. Reported between 2019 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-13362 | Webheadcoder Multi-Step Forms for Contact Form 7 [contact-form-7-multi-step-module] < 4.4.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 4.4.2 | 4.4.2 | 2026-04-30 | ✓ fixed in latest |
| CVE-2023-33999 | Webheadcoder Multi-Step Forms for Contact Form 7 [contact-form-7-multi-step-module] < 4.3.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 4.3.1 | 4.3.1 | 2023-07-18 | ✓ fixed in latest |
| — | Webheadcoder Multi-Step Forms for Contact Form 7 [contact-form-7-multi-step-module] < 4.1.91 | Missing Authorization | Medium 6.3 | < 4.1.91 | 4.1.91 | 2022-03-04 | ✓ fixed in latest |
| — | Webheadcoder Multi-Step Forms for Contact Form 7 [contact-form-7-multi-step-module] < 4.1.91 | — | Unknown | < 4.1.91 | 4.1.91 | 2022-02-28 | ✓ fixed in latest |
| — | Webheadcoder Multi-Step Forms for Contact Form 7 [contact-form-7-multi-step-module] < 4.1.91 | — | Unknown | < 4.1.91 | 4.1.91 | 2022-02-28 | ✓ fixed in latest |
| — | Webheadcoder Multi-Step Forms for Contact Form 7 [contact-form-7-multi-step-module] < 3.0.9 | — | Unknown | < 3.0.9 | 3.0.9 | 2019-03-05 | ✓ fixed in latest |
| — | Webheadcoder Multi-Step Forms for Contact Form 7 [contact-form-7-multi-step-module] < 3.0.9 | — | Unknown | < 3.0.9 | 3.0.9 | 2019-02-25 | ✓ fixed in latest |
| — | Webheadcoder Multi-Step Forms for Contact Form 7 [contact-form-7-multi-step-module] < 3.0.9 | — | Unknown | < 3.0.9 | 3.0.9 | — | ✓ fixed in latest |
+ 2 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update | — | Unknown | < 3.0.9 | 3.0.9 | — | ✓ fixed in latest |
| — | Unauthorised AJAX Calls via Freemius | — | Unknown | < 4.1.91 | 4.1.91 | — | ✓ fixed in latest |
How to fix it
Keep Contact Form 7 Multi Step Module updated — 4.6.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Database Addon for Contact Form 7 – CFDB7 — 600000+ active installs — 100/100 (1874) — max PHP 8.4
- Redirection for Contact Form 7 — 200000+ active installs — 94/100 (275) — max PHP 8.4
- ReCaptcha v2 for Contact Form 7 — 200000+ active installs — 100/100 (89) — max PHP 8.4
- Conditional Fields for Contact Form 7 — 100000+ active installs — 96/100 (166) — max PHP 8.4
- DTX – Dynamic Text Extension for Contact Form 7 — 100000+ active installs — 94/100 (99)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.