Description
Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initialization vector from the HMAC in WPE\FaustWP\Auth\encrypt() and WPE\FaustWP\Auth\decrypt() in plugins/faustwp/includes/auth/functions.php. A logged-in non-administrator who obtains an authorization code from GET /generate can modify the unauthenticated initialization vector so that CBC decryption changes the token type and user identifier while the HMAC remains valid. This can produce an access token for an Administrator and permit full WordPress REST API access, administrator-account creation, plugin installation, and arbitrary code execution. This issue is fixed in repository version 1.8.11.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation and Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

FaustWP authenticates only the ciphertext in its token envelope, excluding the 16‑byte initialization vector from the HMAC. A logged‑in non‑administrator who obtains an authorization code via GET /generate can change the IV. Because the IV is not part of the HMAC, CBC decryption can be manipulated to alter the token's type and user identifier while the HMAC remains valid. This leads to an authentication bypass that grants an attacker an Administrator access token, enabling full WordPress REST API access, creation of administrator accounts, installation of plugins, and ultimately arbitrary code execution on the server.

Affected Systems

The affected product is wpengine's FaustWP WordPress plugin, part of the Faust.js headless WordPress toolkit. Versions prior to 1.8.11 are vulnerable. Users deploying these earlier releases should verify the plugin version and upgrade to 1.8.11 or later.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is less than 1 %, suggesting a low probability of widespread exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. An attacker must be authenticated as a non‑administrator and able to request the /generate endpoint, but no additional privilege is required. Once the malicious request is made, the attacker can generate an administrator‑level token and obtain full control over the WordPress instance.

Generated by OpenCVE AI on September 19, 2026 at 02:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the FaustWP plugin to version 1.8.11 or later.
  • Immediately restrict non‑administrator users from accessing the /generate endpoint until upgrading, or re‑configure permissions so only administrators can call it.
  • Monitor WordPress REST API activity and audit logs to detect abnormal token usage or unauthorized administrator account creation.

Generated by OpenCVE AI on September 19, 2026 at 02:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp Engine
Wp Engine faust.js
Vendors & Products Wordpress
Wordpress wordpress
Wp Engine
Wp Engine faust.js
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initialization vector from the HMAC in WPE\FaustWP\Auth\encrypt() and WPE\FaustWP\Auth\decrypt() in plugins/faustwp/includes/auth/functions.php. A logged-in non-administrator who obtains an authorization code from GET /generate can modify the unauthenticated initialization vector so that CBC decryption changes the token type and user identifier while the HMAC remains valid. This can produce an access token for an Administrator and permit full WordPress REST API access, administrator-account creation, plugin installation, and arbitrary code execution. This issue is fixed in repository version 1.8.11.
Title FaustWP — Authentication Bypass via Initialization Vector Modification in Token Envelope
Weaknesses CWE-345
CWE-639
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
Wp Engine Faust.js
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T18:33:34.727Z

Reserved: 2026-06-12T16:25:43.084Z

Link: CVE-2026-54239

cve-icon Vulnrichment

Updated: 2026-09-18T17:24:08.989Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T19:16:50.047

Modified: 2026-09-24T21:23:54.397

Link: CVE-2026-54239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:45:16Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-639

    Authorization Bypass Through User-Controlled Key