The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Ninja_forms | Ninjaforms | * | 3.13.3 (excluding) |
References