CVE-2026-85097

CRITICAL TTE Zero-Day Pub 08/10 Upd 08/10

Overview

This vulnerability is an unauthenticated arbitrary file upload flaw in the Bricksforge WordPress plugin, caused by improper validation of the 'temporaryFileUploads' parameter during form submission. The root cause lies in the insufficient verification of the attacker-controlled URL field, allowing bypass of MIME type checks. The affected component is the temporary upload directory handling mechanism in Bricksforge versions up to and including 3.1.8.9.

Vulnerability Description

The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a GIF/PHP polyglot file to the temporary upload directory where MIME type validation is correctly performed. Subsequently, the attacker can submit a form with a crafted 'temporaryFileUploads' parameter where the server-side file path points to the validated GIF file, but the attacker-controlled url field ends with a .php extension. This makes it possible for unauthenticated attackers to upload and execute arbitrary PHP code on the server.

Impact

An unauthenticated attacker can execute arbitrary PHP code on the server by uploading and executing malicious files, resulting in full system compromise. This allows unauthorized access to sensitive data, modification or deletion of files, and potential lateral movement within the network. No authentication or user interaction is required, increasing the likelihood of exploitation in exposed environments. The business impact includes data breaches, service disruption, and loss of system integrity.

Solution

Upgrade the Bricksforge plugin to a version later than 3.1.8.9 where this vulnerability is patched, as detailed in the official changelog at https://bricksforge.io/version-changelog/. Wordfence provides an advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/e993c929-f175-43a7-92e6-9d3b089b8dde?source=cve with additional mitigation guidance. Applying the vendor-released update promptly is the recommended remediation step.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products

No CPE information available.

Exploits

No exploits found for this CVE.

Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest HIGH
Sightings Considerable activity

Threat Feed

4 events
2026-10-09
Threat Sensor Sighting — Considerable activity

Sighting activity recorded

2026-10-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-10-07
Detected as Exploited in the Wild

Active exploitation confirmed — vendor: bricksforge, product: bricksforge

Detected as Exploited in the Wild (72 sightings)

Active exploitation confirmed with 72 sighting(s)

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.

Attack Vectors ML

File Upload Vulnerabilities
100% file_upload
Remote Code Execution
52% rce
Path Traversal
49% path_traversal

MITRE ATT&CK Techniques (0)

ATT&CK techniques pending

Techniques are derived from this CVE's kill chains once ML classification completes.

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
35%
High High

Red Team Playbook

AtomicRedTeam integration in progress

Executable commands will be auto-mapped to each ATT&CK technique of this CVE.

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (3)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-85097
wordfence.com
GitHub CVE
https://www.wordfence.com/threat-intel/vulnerabilities/id/e993c929-f175-43a7-92e6-9d3b089b8dde?source=cve
bricksforge.io
GitHub CVE
https://bricksforge.io/version-changelog/