PoC Index

CVE-2025-14072

MEDIUM 5.3EPSS 0.4%

The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.35% chance of exploitation in the next 30 days, 28th percentile
Published
2026-01-02

Proof-of-concept exploits (1)

References

Related