PT-2026-1053 · WordPress · Ninja Forms

Marco Lunardi

·

Published

2026-01-02

·

Updated

2026-01-02

·

CVE-2025-14072

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ninja Forms WordPress plugin versions prior to 3.13.3
Description An unauthenticated attacker can generate valid access tokens through the REST API. These tokens can then be used to read form submissions. The affected API endpoint allows access token generation without authentication. The vulnerable parameter is not specified.
Recommendations Update to version 3.13.3 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2025-14072

Affected Products

Ninja Forms