Loading
The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
Use CWE-79, Wpeverest vendor hub and Everest Forms product page to widen CVE-2021-24907 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-3439, CVE-2025-1128 and CVE-2025-5927 for nearby disclosures in the same product family.