Description

The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.21.0 via the ~/admin/inc/phpinfo.php file that gets created on install. This makes it possible for unauthenticated attackers to extract sensitive data including configuration data.

INFO

Published Date :

2025-10-11T07:25:57.293Z

Last Modified :

2026-04-08T16:57:35.876Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2025-9196 vulnerability.

Vendors Products
Sergiotrinity
  • Trinity Audio
Wordpress
  • Wordpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact