CVE-2025-12139: Princeahmed File Manager For Google Drive – Integrate Google Drive

High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.

The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.5.3 via the "get_localize_data" function. This makes it possible for unauthenticated attackers to extract sensitive data including Google OAuth credentials (client_id and client_secret) and Google account email addresses.

Affected products

  • Princeahmed File Manager For Google Drive – Integrate Google Drive: up to and including 1.5.3

Published 2025-11-05. Last modified 2026-06-17.