Text to Speech for WP (AI Voices by Mementor) WordPress Plugin Sensitive Information Exposure Vulnerability
Vulnerability
A vulnerability allowing sensitive information exposure exists in the Text to Speech for WP (AI Voices by Mementor) WordPress plugin, in all versions prior to 1.9.8. The issue stems from hardcoded MySQL database credentials for the vendor's external telemetry server, located in the 'Mementor_TTS_Remote_Telemetry' class. This flaw enables unauthenticated attackers to extract and decode these credentials, thereby gaining unauthorized write access to the vendor's telemetry database.
Impact
Exploitation of this vulnerability allows for unauthorized access to the vendor's telemetry database, with the ability to write data.
Remediation
Users can update to version 1.9.9 or a newer patched version to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
