Impact
Bricksforge versions up to 3.1.8.9 allow attackers to upload a PHP polyglot file by exploiting the temporaryFileUploads parameter, leading to arbitrary PHP execution. The flaw is a result of insufficient validation of the attacker‑controlled URL field, which enables a remote code execution scenario. Because the vulnerability can be triggered without authentication, any user who can reach the plugin’s form can compromise the site.
Affected Systems
WordPress sites running the Bricksforge plugin, any instance of Bricksforge, version 3.1.8.9 or earlier. The affected plugin is the free or paid Bricksforge WordPress plugin. The vulnerability exists in all distributions of Bricksforge that include the temporaryFileUploads feature.
Risk and Exploitability
The flaw is assigned a CVSS score of 9.8, which indicates critical severity. EPSS is not available, so we lack current probability of exploitation, but the vulnerability is well documented and noted by threat intel. It is not listed in the CISA KEV catalog. The likely attack path involves an unauthenticated user accessing the plugin’s AJAX endpoint, generating a nonce, uploading a GIF/ PHP polyglot file, and then forging a temporaryFileUploads request that points to that file with a .php extension; this enables remote code execution on the web server. Because there is no authentication requirement, attackers can affect any WordPress site that has Bricksforge installed and the temporaryFileUploads functionality enabled.
OpenCVE Enrichment