Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Tue, 02 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability check on its AJAX request handler, allowing users such as contributor to view site options. | |
| Title | Upload.am File Hosting VPN < 1.0.1 - Contributor+ Arbitrary Option Disclosure | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-12-02T16:01:50.833Z
Reserved: 2025-11-03T14:38:34.278Z
Link: CVE-2025-12630
Updated: 2025-12-02T16:01:46.329Z
Status : Deferred
Published: 2025-12-02T16:15:53.720
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-12630
No data.
OpenCVE Enrichment
Updated: 2025-12-03T12:10:07Z
No weakness.