Access Control Vulnerability in Arvow AI SEO Writer WordPress Plugin
CVE-2026-16257

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 August 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-16257?

The Arvow AI SEO Writer WordPress plugin prior to version 1.5.4 contains an access control vulnerability that permits unauthenticated users to exploit a REST endpoint. This flaw arises from inadequate access restrictions, specifically allowing adversaries to bypass security measures via type juggling. As a result, these users can create arbitrary posts and pages, leading to potential disclosure of sensitive author account details and taxonomy information. It is crucial for site administrators to upgrade to the latest version to mitigate associated risks.

Affected Version(s)

Arvow AI SEO Writer 0 < 1.5.4

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pablo González Pérez
Francisco José Ramírez Vicente and Iñigo Sánchez Enciso
WPScan
.