Bricksforge
by WordPress
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-84814 | Cri | 0.64 | 9.8 | 0.00 | Sep 3, 2026 | Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. | ||
| CVE-2024-31244 | Cri | 0.64 | 9.8 | 0.00 | Jun 9, 2024 | Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. | ||
| CVE-2026-18030 | Hig | 0.53 | 8.1 | 0.00 | Aug 10, 2026 | The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and… | ||
| CVE-2026-34888 | Hig | 0.49 | 7.5 | 0.00 | Jun 17, 2026 | Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions. | ||
| CVE-2024-31243 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2024 | Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. | ||
| CVE-2024-31242 | Med | 0.34 | 5.3 | 0.00 | Apr 10, 2024 | Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. | ||
| CVE-2026-14956 | Cri | 0.00 | 9.8 | 0.00 | Jul 17, 2026 | The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to… |
- risk 0.64cvss 9.8epss 0.00
Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
- risk 0.64cvss 9.8epss 0.00
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
- risk 0.53cvss 8.1epss 0.00
The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and…
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions.
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
- risk 0.34cvss 5.3epss 0.00
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
- risk 0.00cvss 9.8epss 0.00
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to…