๐Ÿ” CVE Alert

CVE-2026-54239

HIGH 8.8

FaustWP โ€” Authentication Bypass via Initialization Vector Modification in Token Envelope

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initialization vector from the HMAC in WPE\FaustWP\Auth\encrypt() and WPE\FaustWP\Auth\decrypt() in plugins/faustwp/includes/auth/functions.php. A logged-in non-administrator who obtains an authorization code from GET /generate can modify the unauthenticated initialization vector so that CBC decryption changes the token type and user identifier while the HMAC remains valid. This can produce an access token for an Administrator and permit full WordPress REST API access, administrator-account creation, plugin installation, and arbitrary code execution. This issue is fixed in repository version 1.8.11.

CWE CWE-345 CWE-639
Vendor wpengine
Product faustjs
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for wpengine faustjs

Be the first to know when new high vulnerabilities affecting wpengine faustjs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

wpengine / faustjs
< 1.8.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/wpengine/faustjs/security/advisories/GHSA-q6pm-r77q-qcv3 github.com: https://github.com/wpengine/faustjs/pull/2386 github.com: https://github.com/wpengine/faustjs/commit/cda00de7290f9b178cb1652d30b4cdf5bb8688d0