ZeroHour

CVE-2025-14072

PoC
CVSS 3.1
5.3 medium
EPSS
<1%p28
Published
()
Modified
Description

The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.

Vendors
ninjaforms
Products
ninja forms
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.