CVE Vulnerabilities

CVE-2025-14072

Published: Jan 02, 2026 | Modified: Jan 09, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.

Affected Software

NameVendorStart VersionEnd Version
Ninja_formsNinjaforms*3.13.3 (excluding)

References