Authorization Bypass in Alt Text AI Plugin for WordPress
CVE-2026-91108
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-91108?
The Alt Text AI plugin for WordPress is susceptible to an authorization bypass issue. This vulnerability arises from inadequate user validation, which allows authenticated attackers with subscriber-level access or higher to alter post content across the site, including posts they do not own. Attackers can implement LLM-generated text containing their own keywords, facilitating black-hat SEO tactics and unauthorized usage of the site owner’s paid AltText.ai API credits. The vulnerability is exacerbated by the exposure of a nonce on accessible admin pages, making it easy for any authenticated user to obtain and exploit it.
Affected Version(s)
Alt Text AI – Automatically generate image alt text for SEO and accessibility 0 <= 1.10.41