CVE-2025-14072: Ninjaforms Ninja Forms
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.
Affected products
- Ninjaforms Ninja Forms: before 3.13.3 (fixed in 3.13.3)
Published 2026-01-02. Last modified 2026-06-17.