Product
The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload via the 'temporaryFileUploads' parameter in versions up to 3.1.8.9, enabling remote code execution.