CVE-2021-24907: Everest Forms < 1.8.0 - Reflected Cross-Site Scripting
Published Dec 21, 2021
·Updated
The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
Affected Software
1 affected component
WPEverest Everest Forms Wordpress<1.8.0
Event History
Dec 21, 2021
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-24907.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability is the Contact Form Drag and Drop Form Builder for WordPress plugin before version 1.8.0.
3
What is the severity of CVE-2021-24907?
The severity of CVE-2021-24907 is medium with a CVSS score of 6.1.
4
What is the CWE category for this vulnerability?
The CWE category for this vulnerability is CWE-79 (Improper Neutralization of Input During Web Page Generation).
5
How can I mitigate the vulnerability in CVE-2021-24907?
To mitigate the vulnerability in CVE-2021-24907, update the Contact Form Drag and Drop Form Builder for WordPress plugin to version 1.8.0 or later.