Vulnerabilities and security researches foralttext-ai alttext-ai
Direction: descendingFeb 27, 2026
Alt Text AI – Automatically generate image alt text for SEO and accessibility # CVE-2026-25348
- CVE, Research URL
- Home page URL
- Date
- Feb 19, 2026
- Research Description
- Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Alt Text AI: from n/a through <= 1.10.15.
- Affected versions
-
max 1.10.15.
- Status
-
vulnerable
Apr 23, 2025
Alt Text AI – Automatically generate image alt text for SEO and accessibility # CVE-2025-46232
- CVE, Research URL
- Home page URL
- Date
- Apr 22, 2025
- Research Description
- Missing Authorization vulnerability in alttextai Download Alt Text AI allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Download Alt Text AI: from n/a through 1.9.93.
- Affected versions
-
max 1.9.94.
- Status
-
vulnerable
Jun 07, 2024
Alt Text AI – Automatically generate image alt text for SEO and accessibility # CVE-2024-4847
- CVE, Research URL
- Home page URL
- Date
- May 15, 2024
- Research Description
- The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to generic SQL Injection via the ‘last_post_id’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Affected versions
-
max 1.5.0.
- Status
-
vulnerable
Alt Text AI – Automatically generate image alt text for SEO and accessibility # CVE-2024-34366
- CVE, Research URL
- Home page URL
- Date
- May 07, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AltText.Ai Download Alt Text AI allows Stored XSS.This issue affects Download Alt Text AI: from n/a through 1.3.4.
- Affected versions
-
max 1.3.5.
- Status
-
vulnerable