Sensitive Information Exposure in TNC Toolbox Plugin for WordPress
CVE-2025-12539

10CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 November 2025

What is CVE-2025-12539?

The TNC Toolbox: Web Performance plugin for WordPress is at risk of exposing sensitive information due to the insecure storage of cPanel API credentials within the web-accessible wp-content directory. This vulnerability arises from the inadequate protection in the save_settings function of the plugin. Unauthenticated attackers can access these credentials, potentially allowing them to execute arbitrary file uploads, engage in remote code execution, and completely compromise the hosting environment.

Affected Version(s)

TNC Toolbox: Web Performance * <= 1.4.2

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kenneth Dunn
.
CVE-2025-12539 : Sensitive Information Exposure in TNC Toolbox Plugin for WordPress