Multi-Step Checkout for WooCommerce
Multi-Step Checkout for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Multi-Step Checkout for WooCommerce has a vendor fix available, so running the current release closes it.
All of these findings were reported by benzdeus. Multi-Step Checkout for WooCommerce is installed on roughly 8,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-67542Multi-Step Checkout for WooCommerce <= 2.33 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Multi-Step Checkout for WooCommerce
Author
SilkyPress
woocommerceCreate a better user experience by splitting the checkout process in several steps. This will also improve your conversion rate. The plugin was made with the use of the WooCommerce standard templates. This ensure that it should work with most the themes out there. Nevertheless, if you find that something isn’t properly working, let us know in the Support forum. Features Sleak design Mobile friendly Responsive layout Adjust the main color to your theme Inherit the form and buttons design from your theme Keyboard navigation Available translations German French Tags: multistep checkout, multi-step-checkout, woocommerce, checkout, shop checkout, checkout steps, checkout wizard, checkout style, checkout page
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C