Impact
This vulnerability is an unauthenticated broken access control that allows a remote attacker to bypass the plugin’s authorization checks. Based on the description, it is inferred that an attacker can perform privileged operations such as creating, editing, or deleting content, potentially taking full control of the WordPress site.
Affected Systems
The affected product is the WordPress Arvow AI SEO Writer plugin from Afonso Matos. Versions 1.5.3 and earlier are vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web-based request to the plugin’s endpoints, and because authentication is not required, exploitation can occur from any internet-facing user. While no confirmed exploits have been reported, the high severity and lack of access controls represent a significant risk to site owners.
OpenCVE Enrichment