CVE-2025-12539
The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2. This is due to the plugin storing cPanel API crede...
Affects 0 products across 7 vendors.
The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure due to the insecure storage of cPanel API credentials in web-accessible files.
BSID: BS-2025-GLOBAL-270671-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-12539?
What is the CVSS score for CVE-2025-12539?
Is CVE-2025-12539 actively exploited?
How do I remediate CVE-2025-12539?
What systems are affected by CVE-2025-12539?
| CVE ID | CVE-2025-12539 |
|---|---|
| BSID | BS-2025-GLOBAL-270671-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2025-11-11 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Source | NVD |
The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2. This is due to the plugin storing cPanel API credentials (hostname, username, and API key) in files within the web-accessible wp-content directory without adequate protection in the "Tnc_Wp_Toolbox_Settings::save_settings" function. This makes it possible for unauthenticated attackers to retrieve these credentials and use them to interact with the cPanel API, which can lead to arbitrary file uploads, remote code execution, and full compromise of the hosting environment.
Source: NIST NVD / MITRE CVE Database
An attacker can exploit this vulnerability by accessing the web-accessible files within the wp-content directory to retrieve cPanel API credentials, which could lead to unauthorized access to the cPanel account.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Cpanel | — | — |
| Files | — | — |
| Full | — | — |
| Interact | — | — |
| Plugin | — | — |
| Retrieve | — | — |
| Wordpress | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 8991993760abb0dbd0be574b28b4afc38bb599c10c3e438abf7fd03f022161580a401d1c441c102d7faf9210f37feb88dedeb5bbb9d378fec93b99cde5290b1f |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →