External risk intelligence

Bricksforge WordPress Plugin Arbitrary File Upload Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-85097

The vulnerability affects a WordPress plugin, which is typically used to extend the functionality of public-facing web servers. Because WordPress sites are designed to be accessible over the internet to serve content and process form submissions, this plugin's functionality is inherently exposed to the public internet by design.

Unrestricted File Upload

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in the Bricksforge plugin for WordPress, which could allow unauthenticated attackers to upload and execute arbitrary code on servers. This type of vulnerability can pose a significant risk to system integrity and data security if exploited.

  • Unauthenticated code execution via a file upload flaw.
  • Affects public-facing WordPress sites and their data.
  • Confirm relevance and exposure of this plugin.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by first obtaining a valid security token for the Bricksforge plugin. They would then upload a specially crafted file that tricks the plugin into accepting it as a valid image, but which is actually executable PHP code. Finally, the attacker could submit a form with a malicious request that causes the server to execute the uploaded PHP code, leading to remote code execution on the server.

  • No authentication required to start.
  • Uploading a malicious file and submitting a crafted form.
  • Arbitrary code execution on the server.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to upload and execute arbitrary PHP code on the server when supported by the advisory's conditions. This could lead to a complete compromise of the affected WordPress site.

  • Arbitrary PHP code execution.
  • Uploading malicious files via crafted requests.
  • Complete website compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts the Bricksforge plugin for WordPress, a common component for extending website functionality. The primary responsibility for addressing this will likely fall to the Application Owners or Platform Teams managing the WordPress instances, in coordination with Security Teams for exposure assessment and Vendor Management if the plugin was acquired through third-party channels. The initial action is to inventory all WordPress sites using the Bricksforge plugin, determine their internet reachability and business criticality, and then assign ownership for remediation.

  • Own by: WordPress Application Owners.
  • Verify first: Plugin usage and reachability.
  • Action: Plan coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Bricksforge plugin?

Bricksforge is a toolset designed for the Bricks builder in WordPress. It provides various features to enhance site design and functionality, such as custom interactions and advanced form handling, which developers use to create dynamic user experiences on their websites.

What does CVE-2026-85097 mean?

This vulnerability is an Unrestricted Upload of File with Dangerous Type (CWE-434). In plain terms, the plugin fails to properly validate the file extensions of uploaded content. This allows an attacker to bypass security checks and trick the server into saving and running malicious PHP scripts instead of intended image files.

How does an attacker trigger this vulnerability?

An attacker needs to interact with specific plugin endpoints to succeed. First, they must obtain a valid security nonce from the plugin. They then upload a malicious file disguised as an image and submit a crafted form request. Simply visiting a page or browsing the site does not trigger this issue; it requires an intentional sequence of malicious requests.

Is my WordPress site at risk from this?

According to Halo Surface Signal, this vulnerability is very likely to impact systems because the plugin is designed for public-facing websites. Since WordPress sites are meant to be accessible over the internet to handle form submissions, any instance using this plugin is effectively reachable by an attacker, increasing your risk profile.

What should I do to address this issue?

Start by auditing your environment to identify every WordPress installation that has the Bricksforge plugin installed. Once you have a complete inventory, prioritize these sites based on their business criticality and internet exposure. Coordinate with your platform or security teams to plan the necessary updates or mitigation steps to secure your installations.

References