---
id: CVE-2025-9196
title: >-
  The Trinity Audio – Text to Speech AI audio player to convert content into
  audio plugin for WordPress is vulnerable to Sensitive Information Exposure in
  all versions up to, and including, 5.21.0 via the ~/admin/inc/phpinfo.php file
  that …
summary: >-
  The Trinity Audio – Text to Speech AI audio player to convert content into
  audio plugin for WordPress is vulnerable to Sensitive Information Exposure in
  all versions up to, and including, 5.21.0 via the ~/admin/inc/phpinfo.php file
  that …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
published: '2025-10-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9196'
references:
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3373045%40trinity-audio&new=3373045%40trinity-audio&sfp_email=&sfph_mail=
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/64889659-24d6-40d9-97ba-b448f5205a96?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - exploit-available
epss: 0.01005
epssPercentile: 0.61832
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/MooseLoveti/Trinity-Audio-CVE-Report'
  nuclei:
    - CVE-2025-9196
  checkedAt: '2026-10-08T13:43:30.349Z'
exploitAvailable: true
ingestedAt: '2026-10-08T13:42:55.098Z'
---

## Overview

The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.21.0 via the ~/admin/inc/phpinfo.php file that gets created on install. This makes it possible for unauthenticated attackers to extract sensitive data including configuration data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
