Trinity Audio WordPress Plugin Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing sensitive information exposure has been identified in the Trinity Audio Text to Speech AI WordPress plugin, in all versions through 5.21.0. The issue arises from a phpinfo.php file created during installation, which can be accessed by unauthenticated attackers to extract sensitive data, including configuration information.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, such as configuration data, which could be misused in various ways depending on the nature of the exposed information.

Remediation

Users are advised to update the Trinity Audio WordPress plugin to version 5.22.0 or later.

Added: Oct 11, 2025, 8:17 AM
Updated: Oct 11, 2025, 8:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.1
remediation
7.7
relevance
0.7
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.