The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and take over their account. This vulnerability exists due to the plugin's password reset action in its update mode being vulnerable [truncated]
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to the trusted form-field whitelist. Successful exploitation requires that the site has a public Bricksforge Pro Forms element configu [truncated]
CVE-2026-34888 is a HIGH severity vulnerability (CVSS Score: 7.5) in the Bricksforge plugin versions <= 3.1.8.4. This vulnerability allows unauthenticated sensitive data exposure. The vulnerability was published on 2026-06-17 and last modified on 2026-06-17. Users of affected versions should take immediate action to mitigate the risk. The vendor and product details are not confirmed, with a low confidence [truncated]