CVE-2025-12630: Unknown Upload.am

Medium severity, CVSS 4.9. EPSS: 0.3% chance of exploitation in the next 30 days.

The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability check on its AJAX request handler, allowing users such as contributor to view site options.

Affected products

  • Unknown Upload.am: before 1.0.1 (fixed in 1.0.1)

Published 2025-12-02. Last modified 2026-09-25.