Faust.js
Faust.js has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Faust.js has a vendor fix available, so running the current release closes it.
All of these findings were reported by ParkHyunWoo. Faust.js is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.3.
CVE-2026-49062Faust.js <= 1.8.7 - Missing Authorization
Read the full analysisVulnerability Records

Faust.js
Author
WP Engine
In conjunction with the Faust.js™ NPM packages, the Faust.js™ WordPress plugin enables a decoupled front-end to authenticate with WordPress through GraphQL mutations and REST API endpoints. It is the bridge between a Faust.js™ powered front-end application, and a WordPress backend. The plugin also provides useful options for headless sites, such as the ability to: Hide “theme” admin pages. Redirect public route requests to the front-end application. Rewrite WordPress URLs to front-end URLs in queried content.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C