{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-85097", "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599", "state": "PUBLISHED", "assignerShortName": "Wordfence", "dateReserved": "2026-09-03T01:41:17.605Z", "datePublished": "2026-10-08T06:42:09.676Z", "dateUpdated": "2026-10-08T06:42:09.676Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599", "shortName": "Wordfence", "dateUpdated": "2026-10-08T06:42:09.676Z" }, "affected": [ { "vendor": "Bricksforge", "product": "Bricksforge", "versions": [ { "version": "0", "status": "affected", "lessThanOrEqual": "3.1.8.9", "versionType": "semver" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a GIF/PHP polyglot file to the temporary upload directory where MIME type validation is correctly performed. Subsequently, the attacker can submit a form with a crafted 'temporaryFileUploads' parameter where the server-side file path points to the validated GIF file, but the attacker-controlled url field ends with a .php extension. This makes it possible for unauthenticated attackers to upload and execute arbitrary PHP code on the server." } ], "title": "Bricksforge <= 3.1.8.9 - Unauthenticated Arbitrary File Upload via 'temporaryFileUploads' Parameter", "references": [ { "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e993c929-f175-43a7-92e6-9d3b089b8dde?source=cve" }, { "url": "https://bricksforge.io/version-changelog/" } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "CWE-434 Unrestricted Upload of File with Dangerous Type", "cweId": "CWE-434", "type": "CWE" } ] } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL" } } ], "credits": [ { "lang": "en", "type": "finder", "value": "d.v4n_s3c" } ], "timeline": [ { "time": "2026-09-03T02:05:26.000Z", "lang": "en", "value": "Vendor Notified" }, { "time": "2026-10-07T00:00:00.000Z", "lang": "en", "value": "Disclosed" } ] } } }