CVE

CVE-2026-16257 — Arvow AI SEO Writer [journalist-ai] < 1.5.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16257 Arvow AI SEO Writer [journalist-ai] < 1.5.4 Improper Authentication Unknown < 1.5.4 1.5.4 2026-08-10

CVE-2026-16257

The Arvow AI SEO Writer WordPress plugin, in versions prior to 1.5.4, has a security flaw that allows unauthorized users to access and manipulate certain plugin features. When the plugin is not properly configured, attackers can exploit this vulnerability to create new posts and pages, as well as gain access to sensitive information about authors and taxonomies. This is made possible through a technique called type juggling, which allows attackers to bypass the plugin's access controls and gain unauthorized access to its REST endpoints.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.