Skip to content
Threat Feed
critical advisory

Unauthenticated Arbitrary File Upload in Bricksforge WordPress Plugin

The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload via the 'temporaryFileUploads' parameter in versions up to 3.1.8.9, enabling remote code execution.

CVE search metadata

CVE search record: CVE-2026-85097. Severity: critical. CVSS: 9.8. KEV: no. Product: Bricksforge (<= 3.1.8.9). Brief: Unauthenticated Arbitrary File Upload in Bricksforge WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-85097/

The Bricksforge plugin for WordPress contains a critical vulnerability (CVE-2026-85097) in versions up to and including 3.1.8.9. The flaw arises from improper validation of the 'temporaryFileUploads' parameter during form processing, allowing unauthenticated attackers to achieve remote code execution. By first obtaining a valid nonce from the 'bricksforge_regenerate_nonce' AJAX endpoint, an attacker can upload a malicious GIF/PHP polyglot file. Although the initial upload directory enforces MIME type validation, the attacker can subsequently submit a form referencing this file while manipulating the 'url' field to end with a .php extension. This manipulation forces the server to treat the uploaded file as a PHP script, leading to full site compromise. Defenders should prioritize patching, as this vulnerability allows unauthenticated access and remote code execution without requiring user interaction or administrative privileges.

Attack Chain

  1. The attacker queries the 'bricksforge_regenerate_nonce' AJAX endpoint to obtain a valid nonce for the current session.
  2. The attacker performs an initial file upload request to the Bricksforge temporary upload directory.
  3. The attacker uploads a crafted GIF/PHP polyglot file that passes the server-side MIME type validation check.
  4. The attacker submits a form request containing the 'temporaryFileUploads' parameter.
  5. The attacker injects malicious values into the 'url' field of the 'temporaryFileUploads' parameter.
  6. The server processes the 'url' field, which terminates with a .php extension, causing it to resolve the previously uploaded polyglot file as a executable PHP script.
  7. The server executes the embedded PHP code contained within the GIF, resulting in full remote code execution for the attacker.

Impact

Successful exploitation of CVE-2026-85097 grants an unauthenticated attacker the ability to execute arbitrary PHP code on the hosting server. This typically leads to complete compromise of the WordPress installation, including access to database credentials, exfiltration of sensitive site data, and potentially lateral movement into the hosting environment.

Recommendation

Update the Bricksforge plugin to the latest patched version immediately. Monitor web server access logs for anomalous POST requests directed at temporary upload directories or requests involving the 'bricksforge_regenerate_nonce' endpoint. Deploy WAF rules to intercept POST requests where the 'temporaryFileUploads' parameter contains unexpected URI structures or file extensions.


Immediate actions

Patch Bricksforge plugin to a version > 3.1.8.9

IT Operations 24h

Mitigations

Update Bricksforge plugin

immediate IT Operations

CVE-2026-85097

Detection coverage 1

Detects CVE-2026-85097 Exploitation - Arbitrary File Upload via Bricksforge

high

Detects exploitation attempts against the Bricksforge WordPress plugin by monitoring for requests to the nonce regeneration endpoint followed by suspicious file upload parameters.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →