The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6.5. This is due to the plugin exposing a public AJAX endpoint that retrieves form submission data without performing authorization checks to verify ownership or access rights. This makes it possible for unauthenticated attackers to extract sensitive form submission data including personal information, payment details, and other private data via the rocket_front_payment_seesummary action by enumerating sequential form_r_id values.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Softdiscover
Softdiscover zigaform Wordpress Wordpress wordpress |
|
| Vendors & Products |
Softdiscover
Softdiscover zigaform Wordpress Wordpress wordpress |
Tue, 02 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6.5. This is due to the plugin exposing a public AJAX endpoint that retrieves form submission data without performing authorization checks to verify ownership or access rights. This makes it possible for unauthenticated attackers to extract sensitive form submission data including personal information, payment details, and other private data via the rocket_front_payment_seesummary action by enumerating sequential form_r_id values. | |
| Title | Zigaform <= 7.6.5 - Unauthenticated Form Submission Data Disclosure in rocket_front_payment_seesummary AJAX Endpoint | |
| Weaknesses | CWE-200 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-12-02T14:03:52.290Z
Reserved: 2025-11-25T21:12:12.817Z
Link: CVE-2025-13696
Updated: 2025-12-02T14:02:04.600Z
Status : Awaiting Analysis
Published: 2025-12-02T08:16:00.490
Modified: 2025-12-02T17:16:29.163
Link: CVE-2025-13696
No data.