Impact
The vulnerability is a missing authorization flaw in the alttextai WordPress Download Alt Text AI plugin. The plugin's access control protections are incorrectly configured, allowing an attacker to access plugin functionality and potentially sensitive data. This flaw is classified as a broken access control issue (CWE‑862) and can lead to unauthorized manipulation of alt text settings.
Affected Systems
Affected systems are WordPress installations that have the alttextai Download Alt Text AI plugin installed with version 1.9.93 or earlier. The vendor responsible for the plugin is alttextai. No specific operating system or PHP version is listed, so the vulnerability may exist in any WordPress environment running a vulnerable plugin version.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, and the EPSS score is less than 1 %, suggesting a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers likely would exploit the flaw by sending crafted requests to the plugin’s endpoints, either through authenticated WordPress sessions or potentially unauthenticated access if the plugin exposes any functions outside protected contexts. Because the flaw stems from missing authorization checks, the scope is limited to the plugin’s functions within the WordPress site.
OpenCVE Enrichment
EUVD