Description
The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.
References
https://wpscan.com/vulnerability/4b19a333-eb19-4903-aa96-1fe871dd0f9f/
Third Party AdvisoryExploit
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
5.3 · Medium
Information
Source identifier
Vulnerability status
Analyzed
Published
2026-01-02T06:15:53.627Z
1 week agoLast modified
2026-01-09T13:58:47.983Z
6 days ago