CVE-2026-85097
Last modified
CVE-2026-85097 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a GIF/PHP polyglot file to the temporary upload directory where MIME type validation is correctly performed. Subsequently, the attacker can submit a form with a crafted 'temporaryFileUploads' parameter where the server-side file path points to the validated GIF file, but the attacker-controlled url field ends with a .php extension. This makes it possible for unauthenticated attackers to upload and execute arbitrary PHP code on the server.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Bricksforge | Bricksforge | <= 3.1.8.9 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-85097?
How severe is CVE-2026-85097?
How do I fix CVE-2026-85097?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8509Heap buffer overflow in WebML in Google Chrome prior to 148.…8.8
- CVE-2026-85090FreeRDP before 3.31.0 contains a heap out-of-bounds read vul…5.4
- CVE-2026-85091zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer ov…7.4
- CVE-2026-85092LiME through 1.12.0 fails to validate the disk acquisition o…6.6
- CVE-2026-85093Cheshire Cat AI's GET /memory/collections/{collection_id}/po…6.5
- CVE-2026-85094The Canva Android App before 2.376.0 did not restrict the h…8.8
- CVE-2026-8510Integer overflow in Skia in Google Chrome on Windows prior t…7.5
- CVE-2026-85100A vulnerability was detected in 2FastLabs agent-squad up to …4.3
- CVE-2026-85102Improper certificate trust validation during VPN negotiation…9.8
- CVE-2026-85103A heap-based buffer overflow in VPN certificate ASN.1 decodi…9.8
- CVE-2026-85104In Sooma 2GEN brain stimulator, an attacker within Bluetooth…5.3
- CVE-2026-85105A flaw has been found in NousResearch hermes-agent 0.18.0. A…7.3
Are you affected by CVE-2026-85097?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
