Description
The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a GIF/PHP polyglot file to the temporary upload directory where MIME type validation is correctly performed. Subsequently, the attacker can submit a form with a crafted 'temporaryFileUploads' parameter where the server-side file path points to the validated GIF file, but the attacker-controlled url field ends with a .php extension. This makes it possible for unauthenticated attackers to upload and execute arbitrary PHP code on the server.
Published: 2026-10-08
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Bricksforge versions up to 3.1.8.9 allow attackers to upload a PHP polyglot file by exploiting the temporaryFileUploads parameter, leading to arbitrary PHP execution. The flaw is a result of insufficient validation of the attacker‑controlled URL field, which enables a remote code execution scenario. Because the vulnerability can be triggered without authentication, any user who can reach the plugin’s form can compromise the site.

Affected Systems

WordPress sites running the Bricksforge plugin, any instance of Bricksforge, version 3.1.8.9 or earlier. The affected plugin is the free or paid Bricksforge WordPress plugin. The vulnerability exists in all distributions of Bricksforge that include the temporaryFileUploads feature.

Risk and Exploitability

The flaw is assigned a CVSS score of 9.8, which indicates critical severity. EPSS is not available, so we lack current probability of exploitation, but the vulnerability is well documented and noted by threat intel. It is not listed in the CISA KEV catalog. The likely attack path involves an unauthenticated user accessing the plugin’s AJAX endpoint, generating a nonce, uploading a GIF/ PHP polyglot file, and then forging a temporaryFileUploads request that points to that file with a .php extension; this enables remote code execution on the web server. Because there is no authentication requirement, attackers can affect any WordPress site that has Bricksforge installed and the temporaryFileUploads functionality enabled.

Generated by OpenCVE AI on October 8, 2026 at 07:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Bricksforge to a version newer than 3.1.8.9 or apply the available vendor patch.
  • If an update is not possible, disable the Bricksforge plugin or the temporaryFileUploads endpoint entirely to prevent the upload mechanism.
  • Restrict file uploads to non‑executable MIME types and enforce strict server‑side validation so that PHP files cannot be uploaded or executed.

Generated by OpenCVE AI on October 8, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a GIF/PHP polyglot file to the temporary upload directory where MIME type validation is correctly performed. Subsequently, the attacker can submit a form with a crafted 'temporaryFileUploads' parameter where the server-side file path points to the validated GIF file, but the attacker-controlled url field ends with a .php extension. This makes it possible for unauthenticated attackers to upload and execute arbitrary PHP code on the server.
Title Bricksforge <= 3.1.8.9 - Unauthenticated Arbitrary File Upload via 'temporaryFileUploads' Parameter
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-08T06:42:09.676Z

Reserved: 2026-09-03T01:41:17.605Z

Link: CVE-2026-85097

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T07:16:31.710

Modified: 2026-10-08T07:16:31.710

Link: CVE-2026-85097

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:30:13Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type