Sploitus

CVE-2025-9196

1 known exploit for CVE-2025-9196

The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.21.0 via the ~/admin/inc/phpinfo.php file that gets created on install. This makes it possible for unauthenticated attackers to extract sensitive data including configuration data.

CVSS 3.1
5.3 MEDIUM
EPSS
0.9% (58th percentile)
Weakness
CWE-200
NVD status
Deferred
Published
2025-10-11
CVE-2025-9196 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2025-9196

Proof-of-concept code and exploit modules indexed by Sploitus