Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Hwpark6804-Gif

#31279of 57,635
8.8Total CVSS
Vulnerabilities · 1
PT-2026-95063
8.8
2026-09-17
WordPress · Faustwp · CVE-2026-54239
**Name of the Vulnerable Software and Affected Versions** FaustWP versions prior to 1.8.11 **Description** The FaustWP WordPress plugin fails to include the 16-byte initialization vector in the HMAC (Hash-based Message Authentication Code, a mechanism for verifying data integrity) within the `encrypt()` and `decrypt()` functions. A logged-in non-administrator can obtain an authorization code from the 'GET /generate' endpoint and modify the unauthenticated initialization vector. This allows the attacker to manipulate the token type and user identifier during CBC (Cipher Block Chaining) decryption while keeping the HMAC valid. Consequently, an attacker can generate an Administrator access token, leading to full WordPress REST API access, the creation of administrator accounts, plugin installation, and arbitrary code execution. **Recommendations** Update to version 1.8.11.