Text to Speech for WP (AI Voices by Mementor) WordPress Plugin Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing sensitive information exposure exists in the Text to Speech for WP (AI Voices by Mementor) WordPress plugin, in all versions prior to 1.9.8. The issue stems from hardcoded MySQL database credentials for the vendor's external telemetry server, located in the 'Mementor_TTS_Remote_Telemetry' class. This flaw enables unauthenticated attackers to extract and decode these credentials, thereby gaining unauthorized write access to the vendor's telemetry database.

Impact

Exploitation of this vulnerability allows for unauthorized access to the vendor's telemetry database, with the ability to write data.

Remediation

Users can update to version 1.9.9 or a newer patched version to address this vulnerability.

Added: Apr 4, 2026, 12:19 PM
Updated: Apr 4, 2026, 12:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.1
remediation
0.0
relevance
5.4
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.