PatchSiren cyber security CVE debrief
CVE-2026-85097 Bricksforge CVE debrief
The Bricksforge plugin for WordPress has a critical vulnerability allowing unauthenticated arbitrary file uploads. This issue, tracked as CVE-2026-85097, stems from insufficient validation of the 'temporaryFileUploads' parameter during form submission. An attacker can exploit this by first obtaining a valid nonce, then uploading a malicious GIF/PHP polyglot file. Subsequently, they can submit a crafted form to execute arbitrary PHP code on the server.
- Vendor
- Bricksforge
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
WordPress administrators and users of the Bricksforge plugin should assess their exposure and take necessary actions to mitigate this vulnerability. This includes updating to a patched version of the plugin and monitoring for suspicious activities.
Why it matters
CVE-2026-85097 is a critical vulnerability in the Bricksforge plugin for WordPress, allowing unauthenticated attackers to upload and execute arbitrary PHP code. WordPress administrators and users of the Bricksforge plugin must assess their exposure and apply necessary patches or mitigations immediately.
- Potential execution of arbitrary PHP code on the server.
- Possible unauthorized file uploads.
- Required verification of plugin version and exposure.
- Need for immediate patching or mitigation.
Technical summary
The Bricksforge plugin for WordPress, version 3.1.8.9 or earlier, is vulnerable to unauthenticated arbitrary file uploads. This issue arises from insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An attacker can exploit this vulnerability by first obtaining a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint. They can then upload a malicious GIF/PHP polyglot file to the temporary upload directory. Subsequently, the attacker can submit a crafted form with a 'temporaryFileUploads' parameter that points to the validated GIF file but ends with a .php extension, allowing execution of arbitrary PHP code on the server. Immediate A
Defensive priority
Immediate attention is required to assess exposure and apply necessary patches or mitigations.
Recommended defensive actions
- Assess exposure by confirming if Bricksforge plugin version 3.1.8.9 or earlier is in use.
- Apply the latest patch or update to a version beyond 3.1.8.9.
- Monitor server logs for suspicious file upload activities.
- Consider implementing additional security measures such as Web Application Firewalls (WAFs).
- Review compensating controls for exposed systems while remediation is scheduled.
- Track exceptions and retest remediated assets.
- Verify patch deployment in a controlled change window.
Evidence notes
The vulnerability details are based on the CVE Program record and the source item from cve_program_cvelist_v5. The information provided indicates a high severity issue but does not specify the exact number of affected installations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-85097 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-85097
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-85097 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85097
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Bricksforge <= 3.1.8.9 - Unauthenticated Arbitrary File Upload via 'temporaryFileUploads' Parame
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/85xxx/CVE-2026-85097.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://bricksforge.io/version-changelog/
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.