rootpwn

medium · CVSS v3 4.3 · EPSS 0.00213

CVE-2026-91108

The Alt Text AI WordPress plugin (v1.10.41 and earlier) has an authorization bypass that lets any authenticated subscriber overwrite post co

Overview

The Alt Text AI WordPress plugin (v1.10.41 and earlier) has an authorization bypass that lets any authenticated subscriber overwrite post content with attacker‑controlled LLM‑generated text. This can be used for black‑hat SEO and to consume the paid AltText.ai API credits. The flaw arises because the plugin fails to verify user permissions and exposes a nonce on subscriber‑accessible admin pages.

Description

The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.10.41. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the post_content of any post or page on the site — including content they do not own — with LLM-generated text influenced by attacker-controlled keywords, enabling black-hat SEO manipulation and unauthorized consumption of the site owner's paid AltText.ai API credits. The nonce required to invoke the action is emitted on every admin page including /wp-admin/profile.php, which is accessible to Subscribers, making the nonce trivially obtainable by any authenticated user.

Impact

Confidentiality: attackers can inject malicious or misleading content into posts. Integrity: post content can be overwritten without owner consent. Availability: not directly impacted. Defenders: site owners, content editors, and SEO teams are at risk of content tampering and unexpected API cost inflation.

Remediation

Update the Alt Text AI plugin to the latest version (≥1.10.42) or apply any vendor‑supplied patch. If an update is not immediately possible, restrict subscriber roles from accessing /wp-admin/profile.php or disable the plugin for non‑administrator users. Monitor API usage for abnormal spikes and consider revoking unused API keys.

Risk context

The CVSS v3 score of 4.3 indicates a medium‑risk vulnerability, and the EPSS of 0.00213 suggests a low likelihood of exploitation in the wild. Nonetheless, any authenticated user can exploit the flaw, so prompt remediation is recommended.

Affected products

  • WordPress Alt Text AI plugin
  • WordPress

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.3
CVSS v4
—
EPSS
0.00213

WordPress Alt Text AI Authorization Bypass SEO API Abuse Content Integrity Medium Severity

← All CVEs