Impact
The vulnerability arises from an unauthenticated AJAX endpoint that returns form submission information without verifying the requester's ownership or rights. The exposed data includes personal information and payment details, which could be used in identity theft or fraud. The weakness is a classic sensitive data exposure (CWE-200).
Affected Systems
Softdiscover's Zigaform – Price Calculator & Cost Estimation Form Builder Lite for WordPress, versions up to and including 7.6.5. Users running those releases are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% reflects a low but non‑zero probability of exploitation. The endpoint can be accessed by simply requesting the rocket_front_payment_seesummary action and incrementing sequential form_r_id values, so a threat actor could discover multiple records without any credentials. The vulnerability is not currently cataloged by CISA as a known exploited variant.
OpenCVE Enrichment