Sensitive Information Exposure in Trinity Audio WordPress Plugin
CVE-2025-9196
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 October 2025
What is CVE-2025-9196?
The Trinity Audio plugin for WordPress, which provides text-to-speech capabilities, is susceptible to a vulnerability where sensitive information can be exposed. This occurs due to the creation of the ~/admin/inc/phpinfo.php file during installation, which remains accessible to unauthenticated users. Attackers can exploit this vulnerability to extract confidential data, including important configuration details, potentially compromising the security of the WordPress installation.
Affected Version(s)
Trinity Audio – Text to Speech AI audio player to convert content into audio * <= 5.21.0