PatchSiren

mvirik CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH mvirik CVE published 2026-04-04

CVE-2026-1233

The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress has a sensitive information exposure vulnerability in all versions up to, and including, 1.9.8. This is due to hardcoded MySQL database credentials for the vendor's external telemetry server in the `Mementor_TTS_Remote_Telemetry` class. Unauthenticated attackers can extract and decode these credentials, gaining unauthorized write acces [truncated]