Executive brief
The Arvow AI SEO Writer WordPress plugin contains an authentication bypass flaw that allows unauthenticated attackers to create arbitrary posts and pages on affected websites. When the plugin is freshly installed and not yet configured, attackers can bypass the webhook secret validation through type juggling and inject malicious content, as well as extract sensitive site information including author account details and taxonomy data. This could enable content defacement, spam injection, or reconnaissance for further attacks.
Technical details
The plugin's REST endpoint (/journalistai/v1/webhook) implements insufficient access control by relying solely on a webhook secret that is unset after fresh installation. An unauthenticated attacker can bypass this check through type juggling by sending a JSON boolean (false) instead of the expected string secret, causing the PHP equality check to incorrectly validate the request. The attack requires the plugin to be in its default post-activation state before an administrator configures settings. Successful exploitation allows creation of published posts with arbitrary content, authored by user ID 0, and disclosure of site authors and taxonomy information. The vulnerability was fixed in version 1.5.4.
Affected products
- Arvow AI SEO Writer before 1.5.4
Timeline
- 2026-08-05: disclosed
- 2026-08-10: patched: Fixed in version 1.5.4
- 2026-08-10: advisory