PatchSiren

alttextai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM alttextai CVE published 2026-10-03

CVE-2026-91108

The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to authorization bypass. This allows authenticated attackers with subscriber-level access and above to overwrite post content with LLM-generated text influenced by attacker-controlled keywords, enabling potential black-hat SEO manipulation and unauthorized consumption of paid AltText.ai API [truncated]