Description
Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
Published: 2026-09-03
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability occurs in the WordPress Bricksforge plugin for versions 3.1.8.8 and earlier. It allows an authenticated user with the Subscriber role to elevate privileges and gain higher access levels within the WordPress installation. The weakness is a classic privileged flaw, classified as CWE-266, which results in unauthorized escalation of authority over site content and settings.

Affected Systems

The affected product is the Bricksforge plugin from the vendor Bricksforge, used within WordPress sites. The vulnerability is present in all releases up to and including version 3.1.8.8. No other products or versions are listed as affected.

Risk and Exploitability

The CVSS score of 9.8 indicates a severe risk. Exploitation does not require a separate vulnerability; an attacker only needs to authenticate as a subscriber and then trigger the flaw. The EPSS score is not available, so the likelihood cannot be quantified, but the lack of a KEV listing suggests no known active exploitation at the time of analysis. Given that the plugin is publicly downloadable, a determined attacker with subscriber access could potentially abuse the flaw to obtain administrative rights, compromising confidentiality, integrity, and availability of the site.

Generated by OpenCVE AI on September 3, 2026 at 20:29 UTC.

Remediation

Vendor Solution

Update the WordPress Bricksforge Plugin to the latest available version (at least 3.1.8.9).


OpenCVE Recommended Actions

  • Apply the official patch by updating the Bricksforge plugin to version 3.1.8.9 or newer in the WordPress admin.
  • Verify that the authentication mechanisms restrict the Subscriber role from performing actions that allow privilege escalation, and override any custom role settings if necessary.
  • Review and audit all active plugins in the installation, disable or remove any that are no longer required, and maintain a strict plugin update schedule to ensure future vulnerabilities are patched promptly.

Generated by OpenCVE AI on September 3, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Bricksforge
Bricksforge bricksforge
Wordpress
Wordpress wordpress
Vendors & Products Bricksforge
Bricksforge bricksforge
Wordpress
Wordpress wordpress

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
Title WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Bricksforge Bricksforge
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-03T17:25:47.898Z

Reserved: 2026-09-02T10:29:50.811Z

Link: CVE-2026-84814

cve-icon Vulnrichment

Updated: 2026-09-03T17:25:29.437Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:29.277

Modified: 2026-09-03T18:17:32.233

Link: CVE-2026-84814

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:30:10Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment