## Overview
The Bricksforge plugin for WordPress has a critical vulnerability, CVE-2026-85097, that allows unauthenticated arbitrary file uploads. This affects all versions up to and including 3.1.8.9. The flaw arises from insufficient validation of the URL field in the 'temporaryFileUploads' parameter during form submissions.
## Technical Details
An unauthenticated attacker can exploit this vulnerability by first obtaining a valid nonce through the bricksforge_regenerate_nonce AJAX endpoint. Once they have the nonce, they can upload a crafted GIF/PHP polyglot file to the temporary upload directory. The server performs MIME type validation correctly, but this does not prevent the attacker from manipulating the 'temporaryFileUploads' parameter to point to a PHP file. This allows the attacker to execute arbitrary PHP code on the server.
## Impact
Successful exploitation of this vulnerability can lead to full server compromise. Attackers can upload malicious files and execute them, potentially gaining control over the WordPress installation and the underlying server. This poses a significant risk to any site using the affected versions of the Bricksforge plugin.
## Mitigation
Defenders should immediately update the Bricksforge plugin to the latest version to eliminate this vulnerability. Regularly monitor plugins for updates and apply security patches as soon as they are released. Additionally, review server logs for any suspicious activity that may indicate exploitation attempts.
CSURFACE Threat Sensor