CVE 5.3 MEDIUM

Zigaform <= 7.6.5 - Unauthenticated Form Submission Data Disclosure in rocket_front_payment_seesummary AJAX Endpoint_CVE-2025-13696

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6.5. This is due to the plugin exposing a public AJAX endpoint that retrieves form submission data without performing authorization checks to verify ownership or access rights. This makes it possible for unauthenticated attackers to extract sensitive form submission data including personal information, payment details, and other private data via the rocket_front_payment_seesummary action by enumerating sequential form_r_id values.

Basic Information

ID CVE-2025-13696
Source Wordfence
Published Dec 2, 2025 at 07:24

Affected Product

Vendor softdiscover
Product Zigaform – Price Calculator & Cost Estimation Form Builder Lite
Version *
Affected Versions softdiscover Zigaform – Price Calculator & Cost Estimation Form Builder Lite *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.