CVE-2026-16257: Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling
The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Arvow AI SEO Writerto a version that resolves this vulnerability.Fixed in 1.5.4 - Configuration
Ensure the plugin is properly configured so its REST/webhook access control cannot be bypassed by unauthenticated users via type juggling (problem occurs when the plugin has not been configured).
WordPress plugin: Arvow AI SEO Writer REST endpoint access control (requires proper authorization; webhook secret type-juggling not exploitable) = configured/secured (not left unconfigured)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16257?
The severity of CVE-2026-16257 is rated as 54, indicating a moderate risk associated with the vulnerability.
How do I fix CVE-2026-16257?
To fix CVE-2026-16257, update the Arvow AI SEO Writer plugin to version 1.5.4 or later.
What is CVE-2026-16257?
CVE-2026-16257 is a vulnerability in the Arvow AI SEO Writer WordPress plugin that allows unauthenticated arbitrary post creation due to improper access control.
Who is affected by CVE-2026-16257?
Individuals using the Arvow AI SEO Writer WordPress plugin version prior to 1.5.4 are affected by CVE-2026-16257.
What type of vulnerability is CVE-2026-16257?
CVE-2026-16257 is an unauthenticated arbitrary post creation vulnerability that exploits type juggling within a REST endpoint.