CVE-2026-16257
The Arvow AI SEO Writer WordPress plugin, in versions prior to 1.5.4, has a security flaw that allows unauthorized users to access and manipulate certain plugin features. When the plugin is not properly configured, attackers can exploit this vulnerability to create new posts and pages, as well as gain access to sensitive information about authors and taxonomies. This is made possible through a technique called type juggling, which allows attackers to bypass the plugin's access controls and gain unauthorized access to its REST endpoints.
Based on public CVE data (MITRE/NVD).