CVE-2025-12539

CRITICAL

The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2. This is due to the plugin storing cPanel API crede...

Affects 0 products across 7 vendors.

BCS7.95
CVSS 3.110.0
EPSS1.0%
Percentile61th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-922: CWE-922
◆ SAGE Intelligence — CITED Relevance Research Team

The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure due to the insecure storage of cPanel API credentials in web-accessible files.

BSID: BS-2025-GLOBAL-270671-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-12539?
The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure due to the insecure storage of cPanel API credentials in web-accessible files.
What is the CVSS score for CVE-2025-12539?
CVE-2025-12539 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 1.0%.
Is CVE-2025-12539 actively exploited?
No confirmed active exploitation of CVE-2025-12539 as of 2026-05-30.
How do I remediate CVE-2025-12539?
Priority: IMMEDIATE.
What systems are affected by CVE-2025-12539?
CVE-2025-12539 affects: Cpanel, Files, Full, Interact, Plugin, Retrieve, Wordpress.
Vulnerability Details
CVE IDCVE-2025-12539
BSIDBS-2025-GLOBAL-270671-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2025-11-11
Last Modified2026-04-15
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2. This is due to the plugin storing cPanel API credentials (hostname, username, and API key) in files within the web-accessible wp-content directory without adequate protection in the "Tnc_Wp_Toolbox_Settings::save_settings" function. This makes it possible for unauthenticated attackers to retrieve these credentials and use them to interact with the cPanel API, which can lead to arbitrary file uploads, remote code execution, and full compromise of the hosting environment.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by accessing the web-accessible files within the wp-content directory to retrieve cPanel API credentials, which could lead to unauthorized access to the cPanel account.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cpanel —
Files —
Full —
Interact —
Plugin —
Retrieve —
Wordpress —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 263 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash8991993760abb0dbd0be574b28b4afc38bb599c10c3e438abf7fd03f022161580a401d1c441c102d7faf9210f37feb88dedeb5bbb9d378fec93b99cde5290b1f
Related CVEs affecting Cpanel
CVE-2003-1425 10.0 guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary comm... CVE-2004-1769 10.0 The "Allow cPanel users to reset their password via email" feature in cPanel ... CVE-2004-1770 10.0 The login page for cPanel 9.1.0, and possibly other versions, allows remote a... CVE-2024-8767 9.9 Sensitive data disclosure and manipulation due to unnecessary privileges assi... CVE-2020-26101 9.8 In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a tem...
View all Cpanel CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →