CVE-2026-16257
Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information.
| Vendor | unknown |
| Product | arvow ai seo writer |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown arvow ai seo writer
Be the first to know when new unknown vulnerabilities affecting unknown arvow ai seo writer are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Arvow AI SEO Writer
0 < 1.5.4
References
Credits
Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan