Cyber & AI intelligence
Wasteland.
Briefs indexed3056
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-85097 2026-10-08

Bricksforge WordPress Plugin Flaw Lets Unauthenticated Attackers Upload and Run PHP (CVE-2026-85097)

"CVE-2026-85097 is a critical (CVSS 9.8) unauthenticated arbitrary file upload flaw in the Bricksforge plugin for WordPress, versions up to and including 3.1.8.9, and it can lead to remote code execution."

CVE-2026-85097 is a critical (CVSS 9.8) unauthenticated arbitrary file upload flaw in the Bricksforge plugin for WordPress, versions up to and including 3.1.8.9, and it can lead to remote code execution.

What Is It

CVE-2026-85097 is an unrestricted file upload weakness (CWE-434) in Bricksforge. It comes from weak validation of the attacker-controlled URL field in the temporaryFileUploads parameter when a form is submitted.

According to the NVD description, the attack chain works like this:

  1. An unauthenticated attacker gets a valid nonce from the bricksforge_regenerate_nonce AJAX endpoint.
  2. The attacker uploads a GIF/PHP polyglot file to the temporary upload directory. That file passes MIME type validation, which works correctly at this step.
  3. The attacker submits a form with a crafted temporaryFileUploads parameter. The server-side file path points to the validated GIF, but the attacker-controlled url field ends in .php.

The end result is that an unauthenticated attacker can upload and execute arbitrary PHP code on the server.

Why It Matters

Wordfence scored this flaw CVSS 3.1 9.8 (CRITICAL), with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H:

Running arbitrary PHP on a WordPress host usually means the whole site is compromised.

At the time of writing, CVE-2026-85097 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. This means KEV does not confirm active exploitation, and no federal remediation due date has been set.

What's Vulnerable

The NVD record was published on 2026-10-08 and is in "Received" status. NVD has not yet listed any CPE entries.

Patch Status

The supplied record names no specific fixed version. Because versions through 3.1.8.9 are listed as affected and other versions default to unaffected, site owners should:

Until patched sites are confirmed, administrators should treat any Bricksforge install at 3.1.8.9 or earlier as exposed to unauthenticated code execution. The CVE is not listed in the CISA KEV catalog, so no CISA-mandated required action applies at this time.

Sources