CVE-2025-14072

T

he Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:*

History

09 Jan 2026, 13:58

Type Values Removed Values Added
First Time Ninjaforms
Ninjaforms ninja Forms
CWE NVD-CWE-Other
References () https://wpscan.com/vulnerability/4b19a333-eb19-4903-aa96-1fe871dd0f9f/ - () https://wpscan.com/vulnerability/4b19a333-eb19-4903-aa96-1fe871dd0f9f/ - Third Party Advisory, Exploit
CPE cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:*

02 Jan 2026, 22:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

02 Jan 2026, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-02 06:15

Updated : 2026-01-09 13:58


NVD link : CVE-2025-14072

Mitre link : CVE-2025-14072

CVE.ORG link : CVE-2025-14072


JSON object : View

Products Affected