Unauthenticated Arbitrary File Upload in Bricksforge WordPress Plugin
The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload via the 'temporaryFileUploads' parameter in versions up to 3.1.8.9, enabling remote code execution.
CVE search metadata
CVE search record: CVE-2026-85097. Severity: critical. CVSS: 9.8. KEV: no. Product: Bricksforge (<= 3.1.8.9). Brief: Unauthenticated Arbitrary File Upload in Bricksforge WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-85097/
The Bricksforge plugin for WordPress contains a critical vulnerability (CVE-2026-85097) in versions up to and including 3.1.8.9. The flaw arises from improper validation of the 'temporaryFileUploads' parameter during form processing, allowing unauthenticated attackers to achieve remote code execution. By first obtaining a valid nonce from the 'bricksforge_regenerate_nonce' AJAX endpoint, an attacker can upload a malicious GIF/PHP polyglot file. Although the initial upload directory enforces MIME type validation, the attacker can subsequently submit a form referencing this file while manipulating the 'url' field to end with a .php extension. This manipulation forces the server to treat the uploaded file as a PHP script, leading to full site compromise. Defenders should prioritize patching, as this vulnerability allows unauthenticated access and remote code execution without requiring user interaction or administrative privileges.
Attack Chain
- The attacker queries the 'bricksforge_regenerate_nonce' AJAX endpoint to obtain a valid nonce for the current session.
- The attacker performs an initial file upload request to the Bricksforge temporary upload directory.
- The attacker uploads a crafted GIF/PHP polyglot file that passes the server-side MIME type validation check.
- The attacker submits a form request containing the 'temporaryFileUploads' parameter.
- The attacker injects malicious values into the 'url' field of the 'temporaryFileUploads' parameter.
- The server processes the 'url' field, which terminates with a .php extension, causing it to resolve the previously uploaded polyglot file as a executable PHP script.
- The server executes the embedded PHP code contained within the GIF, resulting in full remote code execution for the attacker.
Impact
Successful exploitation of CVE-2026-85097 grants an unauthenticated attacker the ability to execute arbitrary PHP code on the hosting server. This typically leads to complete compromise of the WordPress installation, including access to database credentials, exfiltration of sensitive site data, and potentially lateral movement into the hosting environment.
Recommendation
Update the Bricksforge plugin to the latest patched version immediately. Monitor web server access logs for anomalous POST requests directed at temporary upload directories or requests involving the 'bricksforge_regenerate_nonce' endpoint. Deploy WAF rules to intercept POST requests where the 'temporaryFileUploads' parameter contains unexpected URI structures or file extensions.
Immediate actions
Patch Bricksforge plugin to a version > 3.1.8.9
Mitigations
Update Bricksforge plugin
CVE-2026-85097
Detection coverage 1
Detects CVE-2026-85097 Exploitation - Arbitrary File Upload via Bricksforge
highDetects exploitation attempts against the Bricksforge WordPress plugin by monitoring for requests to the nonce regeneration endpoint followed by suspicious file upload parameters.
Detection queries are available on the platform. Get full rules →