HomeDefault status
unaffected
Any version before 3.13.3
affected
Description
The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.
Problem types
CWE-287 Improper Authentication
Product status
Any version before 3.13.3
Credits
Marco Lunardi
WPScan
References
wpscan.com/...rability/4b19a333-eb19-4903-aa96-1fe871dd0f9f/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.