Trinity Audio WordPress Plugin Sensitive Information Exposure Vulnerability
Vulnerability
A vulnerability allowing sensitive information exposure has been identified in the Trinity Audio Text to Speech AI WordPress plugin, in all versions through 5.21.0. The issue arises from a phpinfo.php file created during installation, which can be accessed by unauthenticated attackers to extract sensitive data, including configuration information.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive information, such as configuration data, which could be misused in various ways depending on the nature of the exposed information.
Remediation
Users are advised to update the Trinity Audio WordPress plugin to version 5.22.0 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
