What happened
NVD published CVE-2026-91108 (CVSS 4.3) on 2026-10-03 for an authorization bypass in the Alt Text AI plugin up to 1.10.41, where an admin handler runs without proper capability verification.
Why it matters
This is an AI-integrated plugin whose admin actions consume the owner's AI API budget; an authorization bypass lets unauthenticated attackers burn quota and abuse the configured AI service. Low blast radius, precise catalogued CVE.
Attack vector
The plugin's admin handler does not properly verify user authorization (CWE-862), so an unauthenticated attacker can trigger admin-level actions such as bulk alt-text generation against the linked AI provider, consuming the site owner's AI API quota.
Affected systems
Alt Text AI - automatically generate image alt text WordPress plugin <= 1.10.41
Mitigation
Update beyond 1.10.41 when available. Reference: https://plugins.trac.wordpress.org/browser/alttext-ai/tags/1.10.38/admin/class-atai-admin.php#L75