CVE-2026-85097

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a GIF/PHP polyglot file to the temporary upload directory where MIME type validation is correctly performed. Subsequently, the attacker can submit a form with a crafted 'temporaryFileUploads' parameter where the server-side file path points to the validated GIF file, but the attacker-controlled url field ends with a .php extension. This makes it possible for unauthenticated attackers to upload and execute arbitrary PHP code on the server.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-08: 210-08
Referenced assets2 URLs
Full discourse2 posts
  • Security Arsenal, LLC@SecurityAr58409

    🔒 #CyberSecurity CVE-2026-85097: Critical Bricksforge WordPress Plugin RCE via Unauthenticated A… "The NVD has published CVE-2026-85097, a CVSS 9.8 (Critical), network-exploitable…" 🔗 https://securityarsenal.com/blog/cve-2026-85097-critical-bricksforge-wordpress-plugin-rce-via-unauthenticated-arbitrary-file-upload-detection-and-remediation-guide #CyberSecurity #ThreatIntel #cve202685097 #critical #cve

    0000011
    36 followersView on X
  • CVE@CVEnew

    CVE-2026-85097 The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient val… https://www.cve.org/CVERecord?id=CVE-2026-85097

    00000339
    58.1K followersView on X

Explore more