CVE-2025-14072

The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2026-01-02 06:15

Updated : 2026-01-09 13:58


NVD link : CVE-2025-14072

Mitre link : CVE-2025-14072

CVE.ORG link : CVE-2025-14072


JSON object : View

Products Affected

ninjaforms

  • ninja_forms