Description
The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information.
Published: 2026-08-10
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Arvow AI SEO Writer WordPress plugin before version 1.5.4 contains a missing access control on a REST endpoint that can be bypassed by unauthenticated users through type‑juggling. This flaw allows an attacker to create arbitrary posts and pages and to disclose author account and taxonomy information to anyone who can reach the endpoint. The attack therefore permits full content injection and sensitive data exposure without the need for authentication or administrative privileges.

Affected Systems

The vulnerability affects the Arvow AI SEO Writer WordPress plugin for all users running a version older than 1.5.4. No additional versions or configurations have been identified as impacted in the current advisory.

Risk and Exploitability

Because the endpoint is exposed over the web and the bypass requires only a malformed request, the exploitation path is straightforward for unauthenticated users. The CVSS score is 8.2, indicating high severity, while the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA KEV and the combination of unrestricted content creation and information disclosure suggests a severe security risk. An attacker can use this to inject spam, deface a website, or harvest author data for credential‑reuse attacks.

Generated by OpenCVE AI on August 13, 2026 at 11:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Arvow AI SEO Writer plugin to version 1.5.4 or later, as this releases a fixed access control.
  • Deactivate and delete the plugin if it is not required.
  • Configure a web application firewall or security plugin to block unauthenticated POST requests to the exposed REST endpoint until the plugin update is applied.

Generated by OpenCVE AI on August 13, 2026 at 11:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-284

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-284

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information.
Title Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-11T20:14:09.557Z

Reserved: 2026-07-20T08:27:04.142Z

Link: CVE-2026-16257

cve-icon Vulnrichment

Updated: 2026-08-11T20:14:06.478Z

cve-icon NVD

Status : Deferred

Published: 2026-08-10T07:16:47.933

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-16257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T11:45:03Z

Weaknesses