Impact
The AI Image Lab – Free AI Image Generator plugin for WordPress contains a cross‑site request forgery flaw on the wpz-ai-images settings page due to missing or incorrect nonce validation. An unauthenticated attacker can trick a site administrator into clicking a forged link, resulting in the plugin’s API key being overwritten. This does not grant direct remote code execution but gives the attacker control over the key, potentially allowing the attacker to abuse the underlying image‑generation service for malicious purposes.
Affected Systems
All versions of the Aspengrove Studios AI Image Lab – Free AI Image Generator plugin up to and including 1.0.6 are vulnerable. The issue is specific to the wpz-ai-images administrative page exposed within the WordPress admin interface.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity vulnerability. The EPSS score of less than 1% suggests exploitation is unlikely, and the feature is not listed in CISA's KEV catalog. The attack requires social engineering to coerce a site administrator into executing a crafted request, making it a low‑probability event but one that can grant the attacker the ability to manipulate the API key used for image generation services.
OpenCVE Enrichment
EUVD