CVE-2024-4847
📛 CVE Title
Alt Text AI – Automatically generate image alt text for SEO and accessibility <= 1.4.9 - Authenticated (Subscriber+) SQL Injection
Description
The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to generic SQL Injection via the ‘last_post_id’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Wordfence
- CVSS severity
- HIGH
- CVSS score
- 8.8 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Effective score
- 8.8 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-89 - Reserved
- 2024-05-13
- Published
- 2024-05-15 03:56 UTC
- Last updated
- 2026-04-08 18:47 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/4xxx/CVE-2024-4847.json
- Linked Threat
- CVE-2024-4847 — Alt Text AI – Automatically generate image alt text for SEO and accessibility <= 1.4.9 - Authenticated (Subscriber+) SQL Injection
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2024-05-15 02:15:11 UTC
- NVD last modified
- 2026-06-17 08:03:02 UTC
- NVD CVSS v3.1
- 8.8 / 10 HIGH source: security@wordfence.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Exploitability subscore
- 2.8 / 10
- Impact subscore
- 5.9 / 10
- EPSS score
- 0.0061 (probability of exploitation in next 30 days)
- EPSS percentile
- 45.11% vs all CVEs — higher = more likely to be exploited, as of 2026-07-10
NVD / KEV / EPSS data refreshed 2026-07-11 02:47 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2024-44427 - Assigner
- Wordfence
- Published
- May 15, 2024, 1:56:54 AM
- Updated
- Apr 8, 2026, 4:47:21 PM
- EUVD base score (CVSS 3.1)
-
8.8 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EUVD-reported EPSS
- 0.3400
- Vendors
- alttextai
- Products
-
Alt Text AI – Automatically generate image alt text for SEO and accessibility (0 ≤1.4.9)Alt Text AI – Automatically generate image alt text for SEO and accessibility (* ≤1.4.9)
- Aliases
-
GHSA-mgc5-fh63-4wc7
ENISA description: The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to generic SQL Injection via the ‘last_post_id’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
EUVD references (4)
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3c192623-eb46-4f1d-b897-433ac80608cb?source=cve
- https://plugins.trac.wordpress.org/browser/alttext-ai/trunk/includes/class-atai-attachment.php#L677
- https://plugins.trac.wordpress.org/changeset/3086107/
- https://wordpress.org/plugins/alttext-ai/#developers
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| alttextai | Alt Text AI – Automatically generate image alt text for SEO and accessibility |
0 (affected)
|
— |
Vendor references (4)
References embedded in the original CVE record by the assigning CNA.
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3c192623-eb46-4f1d-b897-433ac80608cb?source=cve
- https://plugins.trac.wordpress.org/browser/alttext-ai/trunk/includes/class-atai-attachment.php#L677
- https://plugins.trac.wordpress.org/changeset/3086107/
- https://wordpress.org/plugins/alttext-ai/#developers
MITRE references (4) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3c192623-eb46-4f1d-b897-433ac80608cb?source=cve
- https://plugins.trac.wordpress.org/browser/alttext-ai/trunk/includes/class-atai-attachment.php#L677
- https://plugins.trac.wordpress.org/changeset/3086107/
- https://wordpress.org/plugins/alttext-ai/#developers
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3c192623-eb46-4f1d-b897-433ac80608cb?source=api-prod rapid7:www.wordfence.com
- http://cwe.mitre.org/data/definitions/89.html rapid7:cwe.mitre.org
- https://attackerkb.com/topics/CVE-2024-4847 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44427 rapid7:euvd.enisa.europa.eu
- https://www.cve.org/CVERecord?id=CVE-2024-4847 rapid7:www.cve.org
NVD-tagged references (8)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://plugins.trac.wordpress.org/browser/alttext-ai/trunk/includes/class-atai-attachment.php#L677 security@wordfence.com
- https://plugins.trac.wordpress.org/browser/alttext-ai/trunk/includes/class-atai-attachment.php#L677 af854a3a-2127-422b-91ae-364da2661108
- https://plugins.trac.wordpress.org/changeset/3086107/ security@wordfence.com
- https://plugins.trac.wordpress.org/changeset/3086107/ af854a3a-2127-422b-91ae-364da2661108
- https://wordpress.org/plugins/alttext-ai/#developers security@wordfence.com
- https://wordpress.org/plugins/alttext-ai/#developers af854a3a-2127-422b-91ae-364da2661108
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3c192623-eb46-4f1d-b897-433ac80608cb?source=cve security@wordfence.com
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3c192623-eb46-4f1d-b897-433ac80608cb?source=cve af854a3a-2127-422b-91ae-364da2661108
Indicators (1)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| cve |
CVE-2024-4847
|
no local data | 2026-06-06 14:33 UTC |
Remediations (18)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:techcommunity.microsoft.com
Hi team, Our organization has successfully implemented the recommended mitigation for CVE -2026-42897. However, we are currently experiencing the documented known issues within our environment. Could the Exchange team kindly provide a tentative timeline or ETA for a permanent security update that resolves the underlying vulnerability while addressing these known issues? We would greatly ...
2026-08-05 12:27 UTC -
web:www.wiz.io
Understand the critical aspects of CVE -2025-48384 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.
2026-08-05 12:27 UTC -
web:dailysecurityreview.com
This wave of updates underscores the criticality of monitoring the KEV Catalog for timely vulnerability remediation—especially for federal agencies, which are mandated to patch listed vulnerabilities within defined time frames. Private sector organizations are also strongly advised to assess their exposure and implement risk mitigation measures.
2026-08-05 12:27 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-08-05 12:27 UTC -
web:www.veeam.com
When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information.
2026-08-05 12:27 UTC -
web:www.computing.co.uk
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning over active exploitation of a high-severity vulnerability in the Git distributed version control ...
2026-08-05 12:27 UTC -
web:www.bleepingcomputer.com
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is warning of hackers exploiting an arbitrary code execution flaw in the Git distributed version control system.
2026-08-05 12:27 UTC -
Wordfence remediation: Alt Text AI – Automatically generate image alt text for SEO and accessibilityWordfence
Update to version 1.5.0, or a newer patched version
2026-06-06 14:33 UTC -
web:support.servicenow.com
ServiceNow Posture July, 2024 Description ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington, D.C. Now Platform releases. This vulnerability could
2026-05-22 10:39 UTC -
web:source.android.com
Android partners are encouraged to fix all issues in this bulletin and use the latest security patch level. Devices that use the 2024 -02-01 security patch level must include all issues associated with that security patch level, as well as fixes for all issues reported in previous security bulletins.
2026-05-22 10:39 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 10:39 UTC -
web:petri.com
If a Group Policy setting is available to roll back a fix , it is included in the Windows Update KB article and release notes as a mitigation for a known issue.
2026-05-22 10:39 UTC -
web:www.cybersecuritydive.com
The Cybersecurity and Infrastructure Security Agency added two major software flaws to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, acknowledging the evidence that hackers have been using the bugs in recent attacks. CISA added CVE - 2024 -1708, a high-severity flaw in ConnectWise's ScreenConnect remote-access tool, and CVE -2026-32202, a medium-severity flaw in the Windows Shell ...
2026-05-22 10:39 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 10:39 UTC -
web:www.secure.com
Learn the difference between vulnerability remediation and mitigation , and how a risk-based strategy can strengthen your security posture.
2026-05-22 10:39 UTC -
web:nvd.nist.gov
Description ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers ...
2026-05-22 10:39 UTC -
web:cyberpress.org
The third vulnerability, CVE -2026-44791 (GHSA-wrwr-h859-xh2r), is particularly alarming because it represents a patch bypass. It circumvents the previously issued fix for GHSA-hqr4-h3xv-9m3r in the XML node, reintroducing prototype pollution through a different code path. When chained with additional nodes, this too can escalate to RCE on the host.
2026-05-22 10:39 UTC -
web:cyberinsider.com
Google has released Chrome 148, one of the largest security update batches in the browser's history, patching 127 vulnerabilities.
2026-05-22 10:39 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2024-4847.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-4847",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-05-15T14:02:26.261950Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-06-04T17:56:33.442Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T20:55:10.175Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3c192623-eb46-4f1d-b897-433ac80608cb?source=cve"
},
{
"tags": [
"x_transferred"
],
"url": "https://plugins.trac.wordpress.org/browser/alttext-ai/trunk/includes/class-atai-attachment.php#L677"
},
{
"tags": [
"x_transferred"
],
"url": "https://plugins.trac.wordpress.org/changeset/3086107/"
},
{
"tags": [
"x_transferred"
],
"url": "https://wordpress.org/plugins/alttext-ai/#developers"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Alt Text AI \u2013 Automatically generate image alt text for SEO and accessibility",
"vendor": "alttextai",
"versions": [
{
"lessThanOrEqual": "1.4.9",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Lucio S\u00e1"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Alt Text AI \u2013 Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to generic SQL Injection via the \u2018last_post_id\u2019 parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-08T16:47:21.436Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3c192623-eb46-4f1d-b897-433ac80608cb?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/alttext-ai/trunk/includes/class-atai-attachment.php#L677"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3086107/"
},
{
"url": "https://wordpress.org/plugins/alttext-ai/#developers"
}
],
"timeline": [
{
"lang": "en",
"time": "2024-05-14T11:58:48.000Z",
"value": "Disclosed"
}
],
"title": "Alt Text AI \u2013 Automatically generate image alt text for SEO and accessibility <= 1.4.9 - Authenticated (Subscriber+) SQL Injection"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2024-4847",
"datePublished": "2024-05-15T01:56:54.307Z",
"dateReserved": "2024-05-13T18:02:43.694Z",
"dateUpdated": "2026-04-08T16:47:21.436Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}