{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3abricksforgebricksforgewordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:bricksforge:bricksforge:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-85097"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Bricksforge (\u003c= 3.1.8.9)"],"_cs_severities":["critical"],"_cs_tags":["web-application-vulnerability","wordpress","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["Bricksforge"],"content_html":"\u003cp\u003eThe Bricksforge plugin for WordPress contains a critical vulnerability (CVE-2026-85097) in versions up to and including 3.1.8.9. The flaw arises from improper validation of the 'temporaryFileUploads' parameter during form processing, allowing unauthenticated attackers to achieve remote code execution. By first obtaining a valid nonce from the 'bricksforge_regenerate_nonce' AJAX endpoint, an attacker can upload a malicious GIF/PHP polyglot file. Although the initial upload directory enforces MIME type validation, the attacker can subsequently submit a form referencing this file while manipulating the 'url' field to end with a .php extension. This manipulation forces the server to treat the uploaded file as a PHP script, leading to full site compromise. Defenders should prioritize patching, as this vulnerability allows unauthenticated access and remote code execution without requiring user interaction or administrative privileges.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker queries the 'bricksforge_regenerate_nonce' AJAX endpoint to obtain a valid nonce for the current session.\u003c/li\u003e\n\u003cli\u003eThe attacker performs an initial file upload request to the Bricksforge temporary upload directory.\u003c/li\u003e\n\u003cli\u003eThe attacker uploads a crafted GIF/PHP polyglot file that passes the server-side MIME type validation check.\u003c/li\u003e\n\u003cli\u003eThe attacker submits a form request containing the 'temporaryFileUploads' parameter.\u003c/li\u003e\n\u003cli\u003eThe attacker injects malicious values into the 'url' field of the 'temporaryFileUploads' parameter.\u003c/li\u003e\n\u003cli\u003eThe server processes the 'url' field, which terminates with a .php extension, causing it to resolve the previously uploaded polyglot file as a executable PHP script.\u003c/li\u003e\n\u003cli\u003eThe server executes the embedded PHP code contained within the GIF, resulting in full remote code execution for the attacker.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-85097 grants an unauthenticated attacker the ability to execute arbitrary PHP code on the hosting server. This typically leads to complete compromise of the WordPress installation, including access to database credentials, exfiltration of sensitive site data, and potentially lateral movement into the hosting environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Bricksforge plugin to the latest patched version immediately. Monitor web server access logs for anomalous POST requests directed at temporary upload directories or requests involving the 'bricksforge_regenerate_nonce' endpoint. Deploy WAF rules to intercept POST requests where the 'temporaryFileUploads' parameter contains unexpected URI structures or file extensions.\u003c/p\u003e\n","date_modified":"2026-10-08T08:51:32Z","date_published":"2026-10-08T08:51:32Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-85097/","summary":"The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload via the 'temporaryFileUploads' parameter in versions up to 3.1.8.9, enabling remote code execution.","title":"Unauthenticated Arbitrary File Upload in Bricksforge WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-85097/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:bricksforge:bricksforge:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}