CVE-2021-24907

All FrameworksWordPressCWE-79CVE-2021-24907

CVE-2021-24907

State: PUBLISHED · Published: 2021-12-21 · Updated: 2024-08-03 · Assigner: WPScan
Description
The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2021/24xxx/CVE-2021-24907.json