CVE-2026-85097: critical vulnerability in Bricksforge
Bricksforge <= 3.1.8.9 - Unauthenticated Arbitrary File Upload via 'temporaryFileUploads' Parameter
Published
25Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8
exploitation probability
—
observed exploitation
nono source reports it
The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a GIF/PHP polyglot file to the temporary upload directory where MIME type validation is correctly performed. Subsequently, the attacker can submit a form with a crafted 'temporaryFileUploads' parameter where the server-side file path points to the validated GIF file, but the attacker-controlled url field ends with a .php extension. This makes it possible for unauthenticated attackers to upload and execute arbitrary PHP code on the server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Bricksforge · BricksforgeRelated CVEs — Bricksforge
In the same product, most dangerous first.
CVE-2026-14956CRITICALBricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds ParameterEPSS 0.5%CVE-2026-34888HIGHWordPress Bricksforge plugin <= 3.1.8.4 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-31244CRITICALWordPress Bricksforge plugin <= 2.0.17 - Unauthenticated Arbitrary WordPress Settings Change vulnerabilityEPSS 0.4%CVE-2024-31243HIGHWordPress Bricksforge plugin <= 2.0.17 - Unauthenticated Arbitrary WordPress Setting Deletion vulnerabilityEPSS 0.4%CVE-2024-31242MEDIUMWordPress Bricksforge plugin <= 2.0.17 - Unauthenticated Arbitrary Email Sending vulnerabilityEPSS 0.4%