VYPR

Bricksforge

by WordPress

CVEs (7)

  • CVE-2026-84814CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.00

    Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.

  • CVE-2024-31244CriJun 9, 2024
    risk 0.64cvss 9.8epss 0.00

    Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.

  • CVE-2026-18030HigAug 10, 2026
    risk 0.53cvss 8.1epss 0.00

    The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and…

  • CVE-2026-34888HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions.

  • CVE-2024-31243HigJun 9, 2024
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.

  • CVE-2024-31242MedApr 10, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.

  • CVE-2026-14956CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.00

    The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to…