Vulnerability  ·  2026-10-05

Alt Text AI WordPress plugin: authorization bypass allows unauthenticated action execution

VulnerabilityMedium impactGlobalCVE-2026-91108
NVD published CVE-2026-91108 (CVSS 4.3) on 2026-10-03 for an authorization bypass in the Alt Text AI plugin up to 1.10.41, where an admin handler runs without proper capability verification.
This is an AI-integrated plugin whose admin actions consume the owner's AI API budget; an authorization bypass lets unauthenticated attackers burn quota and abuse the configured AI service. Low blast radius, precise catalogued CVE.
The plugin's admin handler does not properly verify user authorization (CWE-862), so an unauthenticated attacker can trigger admin-level actions such as bulk alt-text generation against the linked AI provider, consuming the site owner's AI API quota.
Alt Text AI - automatically generate image alt text WordPress plugin <= 1.10.41
Update beyond 1.10.41 when available. Reference: https://plugins.trac.wordpress.org/browser/alttext-ai/tags/1.10.38/admin/class-atai-admin.php#L75
NVD CVE-2026-91108
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →