🔐 CVE Alert

CVE-2026-16257

UNKNOWN 0.0

Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information.

Vendor unknown
Product arvow ai seo writer
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for unknown arvow ai seo writer

Be the first to know when new unknown vulnerabilities affecting unknown arvow ai seo writer are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Arvow AI SEO Writer
0 < 1.5.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/89c32854-1cf1-4fe9-a6d0-6244be2dcc03/

Credits

Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan