Impact
The Arvow AI SEO Writer WordPress plugin before version 1.5.4 contains a missing access control on a REST endpoint that can be bypassed by unauthenticated users through type‑juggling. This flaw allows an attacker to create arbitrary posts and pages and to disclose author account and taxonomy information to anyone who can reach the endpoint. The attack therefore permits full content injection and sensitive data exposure without the need for authentication or administrative privileges.
Affected Systems
The vulnerability affects the Arvow AI SEO Writer WordPress plugin for all users running a version older than 1.5.4. No additional versions or configurations have been identified as impacted in the current advisory.
Risk and Exploitability
Because the endpoint is exposed over the web and the bypass requires only a malformed request, the exploitation path is straightforward for unauthenticated users. The CVSS score is 8.2, indicating high severity, while the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA KEV and the combination of unrestricted content creation and information disclosure suggests a severe security risk. An attacker can use this to inject spam, deface a website, or harvest author data for credential‑reuse attacks.
OpenCVE Enrichment