CVE-2025-3201 | Contact Form Builder with Drag & Drop Plugin up to 2.4.2 on WordPress Setting cross site scripting (EUVD-2025-15413)
A vulnerability classified as problematic has been found in Contact Form Builder with Drag & Drop Plugin up to 2.4.2 on WordPress. Affected is an unknown function of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-3201. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.