Sensitive Information Exposure in Trinity Audio WordPress Plugin
CVE-2025-9196
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 October 2025
What is CVE-2025-9196?
The Trinity Audio plugin for WordPress, which provides text-to-speech capabilities, is susceptible to a vulnerability where sensitive information can be exposed. This occurs due to the creation of the ~/admin/inc/phpinfo.php file during installation, which remains accessible to unauthenticated users. Attackers can exploit this vulnerability to extract confidential data, including important configuration details, potentially compromising the security of the WordPress installation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Trinity Audio β Text to Speech AI audio player to convert content into audio * <= 5.21.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved