PT-2026-69351 · WordPress · Arvow Ai Seo Writer
CVE-2026-16257
·
Published
2026-08-10
·
Updated
2026-08-10
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Arvow AI SEO Writer WordPress plugin versions prior to 1.5.4
Description
Insufficient access control in a REST endpoint allows unauthenticated users to bypass security checks via type juggling when the plugin is not configured. Type juggling is a behavior in some programming languages where a variable is automatically converted to a different data type, which can be exploited to bypass comparison checks. This flaw enables attackers to create arbitrary posts and pages, as well as disclose taxonomy information and author account details.
Recommendations
Update Arvow AI SEO Writer WordPress plugin to version 1.5.4 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arvow Ai Seo Writer