PT-2026-69351 · WordPress · Arvow Ai Seo Writer

CVE-2026-16257

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Arvow AI SEO Writer WordPress plugin versions prior to 1.5.4
Description Insufficient access control in a REST endpoint allows unauthenticated users to bypass security checks via type juggling when the plugin is not configured. Type juggling is a behavior in some programming languages where a variable is automatically converted to a different data type, which can be exploited to bypass comparison checks. This flaw enables attackers to create arbitrary posts and pages, as well as disclose taxonomy information and author account details.
Recommendations Update Arvow AI SEO Writer WordPress plugin to version 1.5.4 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16257

Affected Products

Arvow Ai Seo Writer