Impact
The Alt Text AI plugin for WordPress contains a missing authorization flaw that allows any authenticated user with subscriber-level access to overwrite the content of any post or page. By leveraging the atai_enrich_post_content AJAX action, an attacker can inject LLM‑generated text using attacker‑controlled keywords, enabling black‑hat SEO manipulation and draining the site owner’s paid AltText.ai API credits. The vulnerability is rooted in a CWE‑862 missing authorization weakness and is mitigated by the plugin’s failure to verify permissions before performing the update.
Affected Systems
The affected product is the Alt Text AI – Automatically generate image alt text for SEO and accessibility WordPress plugin. All releases up to and including version 1.10.41 are vulnerable; newer releases are not known to contain this flaw.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium impact, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the AJAX endpoint exposed on every admin page, which emits a nonce that is trivially obtainable by any logged‑in subscriber. An attacker only needs an authenticated WordPress account to obtain the nonce and trigger the vulnerable action, making exploitation straightforward for legitimate users with moderate privileges.
OpenCVE Enrichment