Upload.am – File Hosting & VPN

Upload.am – File Hosting & VPN has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Upload.am – File Hosting & VPN has a vendor fix available, so running the current release closes it.

All of these findings were reported by Beatriz Fresno Naumova (beafn28). The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Upload.am – File Hosting & VPN vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2025-12630

Upload.am File Hosting VPN <= 1.0.0 - Authenticated (Contributor+) Arbitrary Options Disclosure

Read the full analysis

Vulnerability Records

1 records
Upload.am – File Hosting & VPN banner
Latestv1.0.1

Upload.am – File Hosting & VPN

Upload.am

Author

Upload.am

0.0(0)
0/100
Last Updated
2025-09-14 (1y ago)
Active Installs
0+
Downloads
533
Requires WP
5.0+
Requires PHP
7.0+
Tested up to
WP 6.8.8
Created
2025-08-11 (1y ago)

This plugin integrates your WordPress site with Upload.am, a file hosting and VPN service. It allows you to upload files directly from the WordPress editor or admin dashboard, manage folders, and embed download links via shortcodes. Key Features: 25 GB free storage Password-protected sharing QR code sharing Ad-free experience Free VPN with multiple locations and zero logs OpenVPN is a registered trademark of OpenVPN Inc. The Upload.am plugin is not affiliated with OpenVPN Inc. Upload.am is an external service (Software as a Service). By using this plugin, you connect to https://upload.am for file storage and VPN features. User data (such as login credentials and uploaded files) is sent to Upload.am servers. For details on data collection and usage, review our Privacy Policy: https://upload.am/privacy.php. Terms of Use: https://upload.am/terms.php. Connection to Upload.am requires explicit user action: logging in via the plugin dashboard. This is an opt-in process — no data is sent without your authentication. The plugin supports both Classic and Gutenberg editors. Shortcode example: [uploadam file="random_digit" text="Download"]. We do not share your personal data with third parties. Prohibited content includes illegal materials — violations lead to bans and reports to authorities. For support: wordpress@upload.am.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C