PT-2025-48651 · WordPress · Zigaform

Published

2025-12-02

·

Updated

2025-12-02

·

CVE-2025-13696

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zigaform versions prior to 7.6.6
Description The Zigaform plugin for WordPress exhibits a sensitive information exposure issue. A public AJAX endpoint allows retrieval of form submission data without authorization checks. This enables unauthenticated attackers to extract sensitive information, including personal data and payment details, by enumerating sequential form r id values through the rocket front payment seesummary action.
Recommendations Update the Zigaform plugin to version 7.6.6 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13696

Affected Products

Zigaform