CVE-2025-12139 is a high-severity information disclosure vulnerability in the File Manager for Google Drive – Integrate Google Drive with WordPress plugin. It affects all versions up to and including 1.5.3. The issue is reported in the plugin's get_localize_data functionality and is associated with exposure of sensitive values through wp_localize_script, causing client-side disclosure of data that should remain server-side. As a result, unauthenticated attackers can retrieve sensitive Google integration data, including Google OAuth client_id, client_secret, and associated Google account email addresses; supporting analysis also indicates exposure of OAuth-related tokens.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Go-based proof-of-concept exploit for CVE-2025-12139, targeting the Integrate Google Drive WordPress plugin (versions up to 1.5.3). The exploit works by sending an HTTP GET request to a user-supplied target URL, parsing the returned HTML for a JavaScript variable ('igd') that is exposed by the vulnerable plugin, and extracting sensitive information such as Google Client ID, Client Secret, and OAuth tokens. The repository consists of two files: the main exploit code (CVE-2025-12139.go) and a README.md that documents the vulnerability, usage instructions, and a screenshot of the exploit in action. The exploit does not require authentication and is effective if the plugin is active and the vulnerable variable is present in the page source. The attack vector is network-based, and the main fingerprintable endpoint is the target's web page where the plugin is active. The exploit is a proof-of-concept and does not weaponize the extracted credentials, but demonstrates the information disclosure risk.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.