Impact
The Ninja Forms plugin for WordPress contains a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback, allowing any unauthenticated user to retrieve form submissions that may include confidential information. This flaw is classified as CWE-862 and results in exposure of data that should be protected by authentication.
Affected Systems
All versions of the Ninja Forms plugin for WordPress up to and including 3.14.1, provided by kstover (Ninja Forms – The Contact Form Builder That Grows With You).
Risk and Exploitability
The CVSS score of 7.5 indicates high severity for information disclosure. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the flaw is reachable via a public REST endpoint that does not require authentication, making it readily exploitable by any web user. The vulnerability is not listed in CISA KEV, yet the publicly exposed endpoint presents a moderate to high risk for sites that rely on Ninja Forms to handle private data.
OpenCVE Enrichment