Description
The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.10.41. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the post_content of any post or page on the site — including content they do not own — with LLM-generated text influenced by attacker-controlled keywords, enabling black-hat SEO manipulation and unauthorized consumption of the site owner's paid AltText.ai API credits. The nonce required to invoke the action is emitted on every admin page including /wp-admin/profile.php, which is accessible to Subscribers, making the nonce trivially obtainable by any authenticated user.
Published: 2026-10-03
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted Post Content Modification by Authenticated Subscribers
Action: Update Immediately
AI Analysis

Impact

The Alt Text AI plugin for WordPress contains a missing authorization flaw that allows any authenticated user with subscriber-level access to overwrite the content of any post or page. By leveraging the atai_enrich_post_content AJAX action, an attacker can inject LLM‑generated text using attacker‑controlled keywords, enabling black‑hat SEO manipulation and draining the site owner’s paid AltText.ai API credits. The vulnerability is rooted in a CWE‑862 missing authorization weakness and is mitigated by the plugin’s failure to verify permissions before performing the update.

Affected Systems

The affected product is the Alt Text AI – Automatically generate image alt text for SEO and accessibility WordPress plugin. All releases up to and including version 1.10.41 are vulnerable; newer releases are not known to contain this flaw.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium impact, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the AJAX endpoint exposed on every admin page, which emits a nonce that is trivially obtainable by any logged‑in subscriber. An attacker only needs an authenticated WordPress account to obtain the nonce and trigger the vulnerable action, making exploitation straightforward for legitimate users with moderate privileges.

Generated by OpenCVE AI on October 3, 2026 at 06:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Alt Text AI to the latest version (1.10.42 or newer) where the authorization check is restored.
  • If an immediate update is not possible, block or restrict the atai_enrich_post_content AJAX endpoint so that only administrators or higher‑privileged roles can invoke it.
  • Reconfigure WordPress user role capabilities to prevent subscribers from editing post content, or remove the subscriber role from sites that rely heavily on the plugin.
  • Monitor post content for unusual changes and audit user activity logs for signs of unauthorized modifications.

Generated by OpenCVE AI on October 3, 2026 at 06:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.10.41. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the post_content of any post or page on the site — including content they do not own — with LLM-generated text influenced by attacker-controlled keywords, enabling black-hat SEO manipulation and unauthorized consumption of the site owner's paid AltText.ai API credits. The nonce required to invoke the action is emitted on every admin page including /wp-admin/profile.php, which is accessible to Subscribers, making the nonce trivially obtainable by any authenticated user.
Title Alt Text AI <= 1.10.41 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Content Modification via atai_enrich_post_content AJAX Action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:45.733Z

Reserved: 2026-09-14T19:34:00.791Z

Link: CVE-2026-91108

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:31.677Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:45.783

Modified: 2026-10-03T16:16:41.383

Link: CVE-2026-91108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T06:45:08Z

Weaknesses