Sceawere

Vulnerability Detail

CVE-2026-85097UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Bricksforge Unauthenticated Arbitrary File Upload

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
4h ago
Vendor
Bricksforge
Product
Bricksforge
Attack Type
CWE-434 Unrestricted Upload of File with Dangerous Type
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a GIF/PHP polyglot file to the temporary upload directory where MIME type validation is correctly performed. Subsequently, the attacker can submit a form with a crafted 'temporaryFileUploads' parameter where the server-side file path points to the validated GIF file, but the attacker-controlled url field ends with a .php extension. This makes it possible for unauthenticated attackers to upload and execute arbitrary PHP code on the server.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-08T07:16:31.710Z",
  "pubdate": "2026-10-08T07:16:31.710Z",
  "executiveSummary": "The Bricksforge WordPress plugin, in versions up to and including 3.1.8.9, contains a critical vulnerability allowing unauthenticated arbitrary file upload and remote code execution (RCE).\nThe flaw stems from insufficient server-side validation of the 'temporaryFileUploads' parameter during form submissions. By manipulating this parameter, an attacker can bypass file extension restrictions and trigger the execution of malicious PHP scripts.\nSuccessful exploitation grants unauthenticated remote attackers the ability to execute arbitrary PHP code within the context of the web server. This compromises the entire WordPress installation, potentially leading to full server compromise, data exfiltration, and unauthorized administrative access.\nBecause the vulnerability can be triggered without prior authentication and involves bypassing security controls, it poses a severe risk to any WordPress environment utilizing the affected versions of Bricksforge. Users are urged to restrict access to relevant endpoints or update the software immediately once a patch is available.",
  "technicalDetails": "The vulnerability resides in the handling of file upload logic within the Bricksforge plugin, specifically regarding the processing of the 'temporaryFileUploads' parameter. While the plugin implements MIME type validation during the initial file upload phase to ensure only specific file types (like images) reach the temporary directory, the post-upload processing logic is flawed.\nThe exploitation flow begins with the attacker interacting with the 'bricksforge_regenerate_nonce' AJAX endpoint to retrieve a valid, non-expired security nonce. This allows the attacker to bypass CSRF protections required for subsequent actions.\nThe attacker proceeds to upload a crafted GIF/PHP polyglot file. A polyglot file is engineered to be valid as an image (passing the plugin's MIME type check) while also containing valid PHP code syntax. Since the MIME type validation only inspects the file header or extension, the server accepts this file and stores it in the temporary upload directory.\nThe core of the vulnerability lies in the subsequent submission of a form that includes a 'temporaryFileUploads' parameter. In this step, the attacker points the server-side file path to the previously uploaded polyglot file. The application fails to strictly validate the user-controlled URL/path field associated with this file. By appending a .php extension to the malicious path or forcing the server to process the polyglot file as a PHP script, the attacker tricks the server into executing the embedded PHP payload.\nBecause the server-side logic trusts the attacker-manipulated path and does not re-verify the integrity or the intended extension of the file during the moving or final processing stage, the PHP interpreter executes the arbitrary code hidden within the image metadata or structure.\nThis vulnerability is classified as an unauthenticated RCE because no valid user session or administrative privilege is required to access the AJAX endpoint or submit the vulnerable form. The network exposure is absolute, as these endpoints are typically accessible via the public-facing HTTP/HTTPS interface of the WordPress site. Post-exploitation impact includes the installation of web shells, backdoors, privilege escalation within the WordPress CMS, or full lateral movement within the hosting infrastructure."
}
CVE-2026-85097: Bricksforge Unauthenticated Arbitrary File Upload (CRITICAL Severity, CVSS: 9.8) | Sceawere