Impact
This vulnerability is a stored cross‑site scripting (XSS) flaw that allows an attacker to inject malicious scripts into web pages generated by the Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin. The flaw arises from improper neutralization of user input when form data is stored and later rendered without escaping. An attacker who can create or edit forms could embed JavaScript that executes in the browsers of anyone who views the affected page, potentially enabling theft of user credentials, session hijacking, or defacement. The weakness is identified as CWE‑79, which indicates a failure to sanitize or encode input properly.
Affected Systems
Affected systems are WordPress sites that host the softdiscover Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin version 7.4.2 or older. All installations of the plugin up to and including 7.4.2 are vulnerable; newer releases should have been patched but are not confirmed here.
Risk and Exploitability
The CVSS score of 7.1 classifies the impact as high. The EPSS score of <1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting there have been no confirmed widespread attacks so far. The attack path requires the ability to add or edit forms, so attackers would need at least some form of authenticated access or a user who can submit form content that feeds into the storage mechanism. Once an attacker successfully injects a payload, it will persist and affect all users who view the page containing the stored content.
OpenCVE Enrichment
EUVD