7.1
CVSSv3

CVE-2025-26989

CVSSv4: NA | CVSSv3: 7.1 | CVSSv2: NA | VMScore: 810 | EPSS: 0.00036 | KEV: Not Included
Published: 03/03/2025 Updated: 03/03/2025

Vulnerability Summary

Stored XSS Vulnerability in Zigaform – Form Builder Lite Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softdiscover Zigaform – Form Builder Lite allows Stored XSS. This issue affects Zigaform – Form Builder Lite: from n/a up to and including 7.4.2.

Solution

Update the WordPress Zigaform – Form Builder Lite wordpress plugin to the latest available version (at least 7.4.3).
Vulnerable Product Search on Vulmon Subscribe to Product

softdiscover zigaform – form builder lite