Impact
FaustWP authenticates only the ciphertext in its token envelope, excluding the 16‑byte initialization vector from the HMAC. A logged‑in non‑administrator who obtains an authorization code via GET /generate can change the IV. Because the IV is not part of the HMAC, CBC decryption can be manipulated to alter the token's type and user identifier while the HMAC remains valid. This leads to an authentication bypass that grants an attacker an Administrator access token, enabling full WordPress REST API access, creation of administrator accounts, installation of plugins, and ultimately arbitrary code execution on the server.
Affected Systems
The affected product is wpengine's FaustWP WordPress plugin, part of the Faust.js headless WordPress toolkit. Versions prior to 1.8.11 are vulnerable. Users deploying these earlier releases should verify the plugin version and upgrade to 1.8.11 or later.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is less than 1 %, suggesting a low probability of widespread exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. An attacker must be authenticated as a non‑administrator and able to request the /generate endpoint, but no additional privilege is required. Once the malicious request is made, the attacker can generate an administrator‑level token and obtain full control over the WordPress instance.
OpenCVE Enrichment