Impact
This vulnerability is a missing authorization flaw in AI Image Alt Text Generator for WP that permits users to access administrative functionality without proper credential checks. The weakness arises from incorrectly configured access control security levels, which can be exploited by attackers who simply request the protected plugin pages. The consequences include the ability to view or modify image alt text data, potentially exposing sensitive information or enabling further manipulation of site content.
Affected Systems
The affected product is WP Messiah Ai Image Alt Text Generator for WP, specifically all releases through version 1.1.9. No additional product or vendor variants are listed.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% shows a low probability of exploitation. The vulnerability is not present in CISA’s KEV catalog. Based on the description, the likely attack vector is through the web interface of the WordPress site; an attacker only needs to target the plugin’s administrative URLs to gain unauthorized access. Once accessed, the attacker can manipulate alt text entries for images across the site, potentially compromising content integrity and facilitating further attacks.
OpenCVE Enrichment