First published: Mon Mar 03 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softdiscover Zigaform – Price Calculator & Cost Estimation Form Builder Lite allows Stored XSS. This issue affects Zigaform – Price Calculator & Cost Estimation Form Builder Lite: from n/a through 7.4.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Zigaform – Price Calculator & Cost Estimation Form Builder Lite | <=7.4.2 | |
Zigaform – Price Calculator & Cost Estimation Form Builder Lite | <=7.4.2 |
Update the WordPress Zigaform – Price Calculator & Cost Estimation Form Builder Lite wordpress plugin to the latest available version (at least 7.4.3).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26994 is considered a high severity vulnerability due to its potential for enabling stored cross-site scripting (XSS) attacks.
To fix CVE-2025-26994, update the Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin to the latest version that addresses the vulnerability.
CVE-2025-26994 can enable attackers to execute malicious scripts in the context of a user's browser, leading to unauthorized actions or data theft.
CVE-2025-26994 affects the Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin for WordPress up to version 7.4.2.
You may be vulnerable to CVE-2025-26994 if you are using an affected version of the Zigaform plugin without the latest security updates.