PatchSiren

Bricksforge CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Bricksforge CVE published 2026-07-17

CVE-2026-14956

The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to the trusted form-field whitelist. Successful exploitation requires that the site has a public Bricksforge Pro Forms element configu [truncated]

HIGH Bricksforge CVE published 2026-06-17

CVE-2026-34888

CVE-2026-34888 is a HIGH severity vulnerability (CVSS Score: 7.5) in the Bricksforge plugin versions <= 3.1.8.4. This vulnerability allows unauthenticated sensitive data exposure. The vulnerability was published on 2026-06-17 and last modified on 2026-06-17. Users of affected versions should take immediate action to mitigate the risk. The vendor and product details are not confirmed, with a low confidence [truncated]