HIGH
mvirik
CVE published 2026-04-04
CVE-2026-1233
The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress has a sensitive information exposure vulnerability in all versions up to, and including, 1.9.8. This is due to hardcoded MySQL database credentials for the vendor's external telemetry server in the `Mementor_TTS_Remote_Telemetry` class. Unauthenticated attackers can extract and decode these credentials, gaining unauthorized write acces [truncated]