PT-2026-95063 · WordPress · Faustwp

·

CVE-2026-54239

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FaustWP versions prior to 1.8.11
Description The FaustWP WordPress plugin fails to include the 16-byte initialization vector in the HMAC (Hash-based Message Authentication Code, a mechanism for verifying data integrity) within the encrypt() and decrypt() functions. A logged-in non-administrator can obtain an authorization code from the 'GET /generate' endpoint and modify the unauthenticated initialization vector. This allows the attacker to manipulate the token type and user identifier during CBC (Cipher Block Chaining) decryption while keeping the HMAC valid. Consequently, an attacker can generate an Administrator access token, leading to full WordPress REST API access, the creation of administrator accounts, plugin installation, and arbitrary code execution.
Recommendations Update to version 1.8.11.

Exploit

Fix

IDOR

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54239
GHSA-Q6PM-R77Q-QCV3

Affected Products

Faustwp