Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-9196 PoC — Trinity Audio <= 5.21.0 - Unauthenticated Information Exposure

Source
Associated Vulnerability
Title:Trinity Audio <= 5.21.0 - Unauthenticated Information Exposure (CVE-2025-9196)
Description:The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.21.0 via the ~/admin/inc/phpinfo.php file that gets created on install. This makes it possible for unauthenticated attackers to extract sensitive data including configuration data.
Readme
# CVE-2025-9196-PoC

This repository contains security research materials and educational demonstrations.
**It is not intended to be used for unauthorized testing, exploitation, or malicious activity.**

**Important:**  
- Any runnable exploit code, payloads, or step-by-step attack instructions have been intentionally **redacted**, **disabled**, or written as **high-level pseudocode** to prevent abuse.  
- Use of material from this repository for illegal activity is strictly prohibited. The owner disclaims liability for misuse.

### Responsible disclosure & access to sensitive details
If you are:
- the affected vendor, or
- a recognized CERT/CSIRT, or
- an experienced, vetted security researcher with a legitimate need


### Responsible usage expectations
By requesting access you agree to:
- Not publish weaponized code or step-by-step exploitation guides publicly.  
- Use the information only for remediation, education, or lawful research.  
- Coordinate any public disclosure with the affected vendor and follow any agreed timelines.



- ![IMG_5780](https://github.com/user-attachments/assets/072c0989-00dc-4bdd-bda6-aaa5257e7522)


File Snapshot

[4.0K] /data/pocs/2047e8b77d4c5edd29ecb53a70de5bd596537428 ├── [518K] CVE-2025-9196-Trinity-phpinfo.php.zip ├── [1.1K] README.md └── [ 245] SECURITY.md 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →