CVE-2025-14072

The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:*

History

09 Jan 2026, 13:58

Type Values Removed Values Added
CWE NVD-CWE-Other
CPE cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/4b19a333-eb19-4903-aa96-1fe871dd0f9f/ - () https://wpscan.com/vulnerability/4b19a333-eb19-4903-aa96-1fe871dd0f9f/ - Third Party Advisory, Exploit
First Time Ninjaforms
Ninjaforms ninja Forms

02 Jan 2026, 22:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

02 Jan 2026, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-02 06:15

Updated : 2026-01-09 13:58


NVD link : CVE-2025-14072

Mitre link : CVE-2025-14072

CVE.ORG link : CVE-2025-14072


JSON object : View

Products Affected

ninjaforms

  • ninja_forms