CVE-2026-1233Disclosure

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL database credentials for the vendor's external telemetry server in the `Mementor_TTS_Remote_Telemetry` class. This makes it possible for unauthenticated attackers to extract and decode these credentials, gaining unauthorized write access to the vendor's telemetry database.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-04); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-04: 2Mentions · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-07: 1Technical Details · 2026-04-04: 2Technical Details · 2026-04-07: 104-0404-07
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-042
Disclosure2
2026-04-071
PoC1
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-1233-text-to-speech-tts-version-1-9-8-high-vulnerability-proof-of-concept CVE-2026-1233 #WordPress plugin #vulnerability text-to-speech-tts #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The tweet links to a proof‑of‑concept for CVE‑2026‑1233, highlighting a high‑severity vulnerability in the WordPress text‑to‑speech‑tts plugin (v1.9.8) with no evidence of active exploitation or patch.

    0000046
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1233 The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This… https://www.cve.org/CVERecord?id=CVE-2026-1233

    Post summary

    The CVE-2026-1233 is disclosed, indicating sensitive information exposure in the Text to Speech for WP plugin up to version 1.9.8, but no exploitation details or patch information are provided.

    00000140
    57.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-1233 - Text to Speech (TTS) by Mementor <= 1.9.8 - Use of Hardcoded Password to Unauthenticated Remote Database Access Intel Report: https://ift.tt/Q1RJtp2

    Post summary

    Announcement of CVE-2026-1233, detailing a hardcoded password issue in Mementor TTS up to version 1.9.8, with no evidence of active exploitation or existing PoC.

    0000051
    281 followersView on X

Explore more