CVE-2026-85097 is a critical (CVSS 9.8) unauthenticated arbitrary file upload flaw in the Bricksforge plugin for WordPress, versions up to and including 3.1.8.9, and it can lead to remote code execution.
What Is It
CVE-2026-85097 is an unrestricted file upload weakness (CWE-434) in Bricksforge. It comes from weak validation of the attacker-controlled URL field in the temporaryFileUploads parameter when a form is submitted.
According to the NVD description, the attack chain works like this:
- An unauthenticated attacker gets a valid nonce from the
bricksforge_regenerate_nonceAJAX endpoint. - The attacker uploads a GIF/PHP polyglot file to the temporary upload directory. That file passes MIME type validation, which works correctly at this step.
- The attacker submits a form with a crafted
temporaryFileUploadsparameter. The server-side file path points to the validated GIF, but the attacker-controlledurlfield ends in.php.
The end result is that an unauthenticated attacker can upload and execute arbitrary PHP code on the server.
Why It Matters
Wordfence scored this flaw CVSS 3.1 9.8 (CRITICAL), with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H:
- It can be attacked over the network.
- Attack complexity is low.
- No privileges or user interaction are needed.
- The impact on confidentiality, integrity and availability is high.
Running arbitrary PHP on a WordPress host usually means the whole site is compromised.
At the time of writing, CVE-2026-85097 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. This means KEV does not confirm active exploitation, and no federal remediation due date has been set.
What's Vulnerable
- Vendor: Bricksforge
- Product: Bricksforge (WordPress plugin)
- Affected versions: all versions up to and including 3.1.8.9
- Default status for other versions: unaffected, per the CNA record
The NVD record was published on 2026-10-08 and is in "Received" status. NVD has not yet listed any CPE entries.
Patch Status
The supplied record names no specific fixed version. Because versions through 3.1.8.9 are listed as affected and other versions default to unaffected, site owners should:
- Check the Bricksforge version changelog for a release later than 3.1.8.9.
- Update as soon as one is available.
Until patched sites are confirmed, administrators should treat any Bricksforge install at 3.1.8.9 or earlier as exposed to unauthenticated code execution. The CVE is not listed in the CISA KEV catalog, so no CISA-mandated required action applies at this time.