Feed/CVE-2025-14072
CVE-2025-14072MEDIUMCVSS 5.3

CVE-2025-14072

Published Jan 2, 2026·Updated Jun 17, 2026

NVD Description

The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free