{"api_version":"1","generated_at":"2026-08-10T11:35:45+00:00","cve":"CVE-2026-16257","urls":{"html":"https://cve.report/CVE-2026-16257","api":"https://cve.report/api/cve/CVE-2026-16257.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-16257","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-16257"},"summary":{"title":"Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling","description":"The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-10 07:16:47","updated_at":"2026-08-10 07:16:47"},"problem_types":["CWE-287 Improper Authentication"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/89c32854-1cf1-4fe9-a6d0-6244be2dcc03/","name":"https://wpscan.com/vulnerability/89c32854-1cf1-4fe9-a6d0-6244be2dcc03/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-16257","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16257","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Arvow AI SEO Writer","version":"affected 1.5.4 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Pablo González Pérez","lang":"en"},{"source":"CNA","value":"Francisco José Ramírez Vicente and Iñigo Sánchez Enciso","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Arvow AI SEO Writer","vendor":"Unknown","versions":[{"lessThan":"1.5.4","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Pablo González Pérez"},{"lang":"en","type":"finder","value":"Francisco José Ramírez Vicente and Iñigo Sánchez Enciso"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information."}],"problemTypes":[{"descriptions":[{"description":"CWE-287 Improper Authentication","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-10T06:00:11.241Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/89c32854-1cf1-4fe9-a6d0-6244be2dcc03/"}],"source":{"discovery":"EXTERNAL"},"title":"Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-16257","datePublished":"2026-08-10T06:00:11.241Z","dateReserved":"2026-07-20T08:27:04.142Z","dateUpdated":"2026-08-10T06:00:11.241Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 07:16:47","lastModifiedDate":"2026-08-10 07:16:47","problem_types":["CWE-287 Improper Authentication"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"16257","Ordinal":"1","Title":"Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Cre","CVE":"CVE-2026-16257","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"16257","Ordinal":"1","NoteData":"The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information.","Type":"Description","Title":"Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Cre"}]}}}