Sensitive Information Exposure in Trinity Audio WordPress Plugin
CVE-2025-9196

5.3MEDIUM

What is CVE-2025-9196?

The Trinity Audio plugin for WordPress, which provides text-to-speech capabilities, is susceptible to a vulnerability where sensitive information can be exposed. This occurs due to the creation of the ~/admin/inc/phpinfo.php file during installation, which remains accessible to unauthenticated users. Attackers can exploit this vulnerability to extract confidential data, including important configuration details, potentially compromising the security of the WordPress installation.

Affected Version(s)

Trinity Audio – Text to Speech AI audio player to convert content into audio * <= 5.21.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Moose Love
.
CVE-2025-9196 : Sensitive Information Exposure in Trinity Audio WordPress Plugin