---
id: CVE-2026-16257
title: >-
  The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly
  restrict access to one of its REST endpoints, whose only access control can be
  bypassed by unauthenticated users through type juggling when the Arvow AI SEO
  Writer W…
summary: >-
  The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly
  restrict access to one of its REST endpoints, whose only access control can be
  bypassed by unauthenticated users through type juggling when the Arvow AI SEO
  Writer W…
severity: none
published: '2026-08-10'
updated: '2026-08-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16257'
references:
  - url: 'https://wpscan.com/vulnerability/89c32854-1cf1-4fe9-a6d0-6244be2dcc03/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-08-10T08:39:25.850Z'
epss: 0.0036
epssPercentile: 0.27111
---

## Overview

The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
