cleantalk
Vulnerabilities and Security Researches

Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease!, CVE-2021-24907

CVE, Research URL

CVE-2021-24907

Published on
Dec 21, 2021
Research Description
The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
Affected versions
Min -, max 1.8.0.
Status
vulnerable