CVE-2024-13362
Contact Form 7 Multi-Step Forms
Minimum safe version
4.4.2
Update to 4.4.2 or later to address 9 fixable vulnerabilities
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Contact Form 7 Multi-Step Forms Plugin < 4.3.1 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
WordPress Contact Form 7 Multi-Step Forms plugin <= 3.0.8 - Authenticated Option Update vulnerability (Fremius Library security issue)
WordPress Contact Form 7 Multi-Step Forms plugin < 4.1.91 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
WordPress Contact Form 7 Multi-Step Forms plugin < 4.1.91 - Sensitive Information Disclosure vulnerability