Security Alert Summary
The Bricksforge WordPress plugin contains an unauthenticated arbitrary file upload vulnerability affecting versions up to and including 3.1.8.9. An attacker can obtain a valid nonce via the AJAX bricksforge_regenerate_nonce endpoint, upload a GIF/PHP polyglot to the temporary upload directory, and then submit a crafted temporaryFileUploads parameter where the attacker-controlled url ends with .php, allowing upload and execution of arbitrary PHP code.
CVE Details
- CVE ID:
CVE-2026-85097 - Affected component: Bricksforge plugin for WordPress
- Affected versions: Up to and including 3.1.8.9
- Published: October 8, 2026 at 07:16:31 AM UTC
- Last modified: October 8, 2026 at 03:17:56 PM UTC
- CVSS v3.1: Base Score 9.8, Severity CRITICAL, Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Authentication / Privileges / User interaction: No authentication required; privileges required: None; user interaction: None
- Primary impact: Confidentiality: High; Integrity: High; Availability: High
- Weakness (CWE): CWE-434
Technical Details
The vulnerability is caused by insufficient validation of an attacker-controlled url field within the temporaryFileUploads parameter during form submission. An unauthenticated attacker can first obtain a valid nonce using the AJAX endpoint bricksforge_regenerate_nonce, then upload a GIF/PHP polyglot file to the plugin’s temporary upload directory where MIME type validation accepts the file. The attacker then submits a form in which the server-side file path references the validated GIF while the attacker-controlled url field ends with .php. The mismatch between the validated file path and the attacker-supplied URL extension enables upload and execution of PHP code on the server.
The issue stems from inadequate server-side checks of the temporaryFileUploads parameter and its nested fields, allowing the application to accept a validated file path while trusting an attacker-controlled URL extension.
How This Could Impact Your Website
Consider a small business site where the owner manages plugins, internal staff (editors or content managers) perform regular updates, and external contractors or contributors handle uploads or content. An unauthenticated attacker exploiting this flaw could upload and execute PHP code, potentially exposing internal user information (for example, email addresses), modifying stored content, or causing service disruption consistent with the CVSS impact ratings.
This elevation of risk could lead to increased targeted phishing or social engineering if internal emails or account data are accessed. If youre unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review.
Recommended Actions
- Update the affected plugin as soon as a patched version is available.
- Review and reduce unnecessary user roles, especially contributors and external users.
- Enforce strong passwords and two-factor authentication for editors and administrators.
- Remove unused or unmaintained plugins.
- Monitor site activity and logs for unusual file uploads or execution behavior.
If youd like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.
References
- https://bricksforge.io/version-changelog/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e993c929-f175-43a7-92e6-9d3b089b8dde?source=cve