WordPress security by component
bricksforge
bricksforge (bricksforge) is a WordPress plugin with 7 published CVE records in this archive. The latest tracked vulnerability was published Sep 03, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
bricksforgeLatest vulnerability
CVE-2026-84814: Bricksforge subscribers can escalate privileges
Bricksforge through 3.1.8.8 allows a Subscriber to cross the plugin's authorization boundary and obtain elevated privileges. Successful exploitation can compromise site confidentiality, integrity, and availability.
| Safe version |
|
||
|---|---|---|---|
| Sep 03, 2026 |
CVE-2026-84814
Bricksforge subscribers can escalate privileges
Bricksforge through 3.1.8.8 allows a Subscriber to cross the plugin's authorization boundary and obtain elevated privileges. Successful exploitation can compromise site confidentiality, integrity, and availability.
|
3.1.8.9 |
CVE9.8
NVDPending
|
| Aug 10, 2026 |
CVE-2026-18030
Bricksforge Pro Forms permits unauthenticated arbitrary password reset
Bricksforge before 3.1.8.8 fails to verify the requester's identity when a Pro Forms form uses the password-reset action in update mode. Server-side current-password verification is disabled by default for that action, so an unauthenticated attacker can set an arbitrary password for any user, including an Administrator, and take over the account.
|
3.1.8.8 |
CVE8.1
NVDPending
|
| Jul 17, 2026 |
CVE-2026-14956
Bricksforge: Privilege escalation or authentication bypass
Bricksforge is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 3.1.8.6.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Jun 17, 2026 |
CVE-2026-34888
Bricksforge: Sensitive information exposure
Bricksforge is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is n/a through 3.1.8.4.
|
3.1.8.5 |
CVE7.5
NVDPending
|
| Jun 09, 2024 |
CVE-2024-31244
Bricksforge: A security weakness
Bricksforge is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.8
NVD7.5
|
| Jun 09, 2024 |
CVE-2024-31243
Bricksforge: A security weakness
Bricksforge is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Apr 10, 2024 |
CVE-2024-31242
Bricksforge: A security weakness
Bricksforge is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|