WordPress · Faustwp · CVE-2026-54239
**Name of the Vulnerable Software and Affected Versions**
FaustWP versions prior to 1.8.11
**Description**
The FaustWP WordPress plugin fails to include the 16-byte initialization vector in the HMAC (Hash-based Message Authentication Code, a mechanism for verifying data integrity) within the `encrypt()` and `decrypt()` functions. A logged-in non-administrator can obtain an authorization code from the 'GET /generate' endpoint and modify the unauthenticated initialization vector. This allows the attacker to manipulate the token type and user identifier during CBC (Cipher Block Chaining) decryption while keeping the HMAC valid. Consequently, an attacker can generate an Administrator access token, leading to full WordPress REST API access, the creation of administrator accounts, plugin installation, and arbitrary code execution.
**Recommendations**
Update to version 1.8.11.