PT-2026-95063 · WordPress · Faustwp
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FaustWP versions prior to 1.8.11
Description
The FaustWP WordPress plugin fails to include the 16-byte initialization vector in the HMAC (Hash-based Message Authentication Code, a mechanism for verifying data integrity) within the
encrypt() and decrypt() functions. A logged-in non-administrator can obtain an authorization code from the 'GET /generate' endpoint and modify the unauthenticated initialization vector. This allows the attacker to manipulate the token type and user identifier during CBC (Cipher Block Chaining) decryption while keeping the HMAC valid. Consequently, an attacker can generate an Administrator access token, leading to full WordPress REST API access, the creation of administrator accounts, plugin installation, and arbitrary code execution.Recommendations
Update to version 1.8.11.
Exploit
Fix
IDOR
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Faustwp