Description
Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.
Published: 2026-08-13
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an unauthenticated broken access control that allows a remote attacker to bypass the plugin’s authorization checks. Based on the description, it is inferred that an attacker can perform privileged operations such as creating, editing, or deleting content, potentially taking full control of the WordPress site.

Affected Systems

The affected product is the WordPress Arvow AI SEO Writer plugin from Afonso Matos. Versions 1.5.3 and earlier are vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity level. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web-based request to the plugin’s endpoints, and because authentication is not required, exploitation can occur from any internet-facing user. While no confirmed exploits have been reported, the high severity and lack of access controls represent a significant risk to site owners.

Generated by OpenCVE AI on August 13, 2026 at 17:05 UTC.

Remediation

Vendor Solution

Update the WordPress Arvow AI SEO Writer Plugin to the latest available version (at least 1.5.4).


OpenCVE Recommended Actions

  • Update the WordPress Arvow AI SEO Writer Plugin to version 1.5.4 or later.
  • Configure role‑based access controls to restrict plugin admin pages to administrators only, ensuring that no non‑admin user can trigger privileged actions.
  • Disable or remove the plugin from the site until the patch is applied to prevent remote exploitation via its exposed endpoints.

Generated by OpenCVE AI on August 13, 2026 at 17:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Afonso Matos
Afonso Matos arvow Ai Seo Writer
Wordpress
Wordpress wordpress
Vendors & Products Afonso Matos
Afonso Matos arvow Ai Seo Writer
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.
Title WordPress Arvow AI SEO Writer plugin <= 1.5.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Afonso Matos Arvow Ai Seo Writer
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:30:59.316Z

Reserved: 2026-07-27T09:00:40.310Z

Link: CVE-2026-66469

cve-icon Vulnrichment

Updated: 2026-08-13T15:30:54.229Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T14:17:08.380

Modified: 2026-08-14T19:09:39.140

Link: CVE-2026-66469

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T09:31:38Z

Weaknesses