Junglewise Threat Intelligence

CVE-2026-49062: WP Engine Faust.js authentication bypass in password recovery

CVE-2026-49062 · Severity: high · CVSS 8.8 · Published 2026-06-15

Executive brief

WP Engine Faust.js, a framework used to build headless WordPress sites, contains a security flaw in its authentication process. An attacker could exploit this vulnerability to bypass security checks and gain unauthorized access to user accounts, including administrative accounts, by manipulating the password recovery process. This could lead to a full takeover of the website, data theft, or service disruption.

Technical details

An authentication bypass vulnerability (CWE-288) exists in WP Engine Faust.js through version 1.8.7. The flaw resides in the password recovery mechanism, where an attacker can use an alternate path or channel to circumvent standard authentication requirements. While the CVSS vector indicates low privileges (PR:L) are required, the exploit allows for privilege escalation to higher-level accounts, potentially granting full administrative access. The vulnerability is remediated in version 1.8.8.

Affected products

  • WP Engine Faust.js <= 1.8.7

Timeline

  • 2026-05-18: other: Reported by ParkHyunWoo
  • 2026-06-08: patched: Version 1.8.8 released
  • 2026-06-15: advisory: NVD publication date

References