Critical Arbitrary File Upload Vulnerability in Bricksforge Plugin Actively Exploited
A critical unauthenticated arbitrary file upload vulnerability (CVE-2026-85097) in the Bricksforge WordPress plugin is being actively exploited in the wild, allowing attackers to achieve remote code execution.

A critical vulnerability, tracked as CVE-2026-85097, has been discovered in the popular Bricksforge WordPress plugin, enabling unauthenticated attackers to upload and execute arbitrary PHP code on vulnerable websites. This flaw, which carries a CVSS score of 10.0, allows for remote code execution (RCE) and affects all versions of Bricksforge up to and including 3.1.8.9. Patchstack, a security firm that identified the vulnerability, has confirmed active exploitation in the wild, with initial activity observed on October 7, 2026.
The Bricksforge plugin extends the functionality of Bricks Builder, a visual website-building tool for WordPress, by adding features for dynamic websites, advanced forms, and custom interactions. Its popularity makes this vulnerability a significant threat to a large number of WordPress sites.
The vulnerability arises from a flaw in how Bricksforge handles file uploads. While the plugin initially validates a file's MIME type, it later trusts metadata provided by the client when a form is submitted. Specifically, the url field within the temporaryFileUploads parameter is not properly validated. This oversight creates a pathway for attackers to upload a file that appears to be a benign image but contains embedded PHP code.
Attackers can exploit this by first obtaining a valid nonce from the Bricksforge REST API. They then upload a GIF or PHP polyglot file, which passes the initial MIME type check and is stored in a temporary directory. The crucial step involves submitting a form where the file path points to this uploaded file, but the url field is manipulated to have a PHP extension. Bricksforge then moves the file to the specified PHP location, allowing the embedded PHP code to be executed when the file is accessed.
Patchstack's telemetry indicates that exploitation attempts are actively occurring, primarily targeting the Bricksforge REST API form submission endpoint (/wp-json/bricksforge/v1/form_submit) and occasionally the admin-ajax.php endpoint. Attackers are observed using various techniques to bypass potential filters, including alternative PHP extensions (e.g., .php5, .phtml), case manipulation (e.g., .PHP), and encoded extensions (e.g., %2ephp). Some payloads aim to place malicious files in the regular WordPress uploads directory.
The exploitation patterns observed suggest coordinated, automated activity. Clusters of requests with identical payloads and variations of PHP extensions point towards automated exploitation tools operating over distributed infrastructure or rotating proxies. While this indicates a sophisticated attack, it does not yet attribute the activity to a specific threat actor.
A fix for CVE-2026-85097 is available in Bricksforge version 3.1.8.10. Organizations running affected versions are strongly urged to update immediately to mitigate the risk of compromise. Patchstack has also deployed mitigation rules to protect its users from exploitation attempts.
This incident highlights the ongoing threat posed by vulnerabilities in popular WordPress plugins, which often serve as entry points for attackers seeking to gain control of websites, deploy malware, or steal sensitive data. The active exploitation of this flaw underscores the importance of timely patching and robust security monitoring for all WordPress installations.