CVE-2025-14072
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.
Affected (1)
Products: Ninjaforms: Ninja Forms
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.13.3 |
References (1)
Source: contact@wpscan.com
ExploitThird Party Advisory
Timeline
No history available yet.