← WordPress Vulnerabilities
WordPress security by component

bricksforge

bricksforge (bricksforge) is a WordPress plugin with 7 published CVE records in this archive. The latest tracked vulnerability was published Sep 03, 2026; the highest published CVSS base score is 9.8.

Plugin slug: bricksforge

CVE-2026-84814: Bricksforge subscribers can escalate privileges

Bricksforge through 3.1.8.8 allows a Subscriber to cross the plugin's authorization boundary and obtain elevated privileges. Successful exploitation can compromise site confidentiality, integrity, and availability.

PublishedSep 03, 2026
Known safe version3.1.8.9
Published vulnerabilities for bricksforge
Safe version
Sep 03, 2026 CVE-2026-84814
Bricksforge subscribers can escalate privileges
Bricksforge through 3.1.8.8 allows a Subscriber to cross the plugin's authorization boundary and obtain elevated privileges. Successful exploitation can compromise site confidentiality, integrity, and availability.
3.1.8.9
CVE9.8
NVDPending
Aug 10, 2026 CVE-2026-18030
Bricksforge Pro Forms permits unauthenticated arbitrary password reset
Bricksforge before 3.1.8.8 fails to verify the requester's identity when a Pro Forms form uses the password-reset action in update mode. Server-side current-password verification is disabled by default for that action, so an unauthenticated attacker can set an arbitrary password for any user, including an Administrator, and take over the account.
3.1.8.8
CVE8.1
NVDPending
Jul 17, 2026 CVE-2026-14956
Bricksforge: Privilege escalation or authentication bypass
Bricksforge is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 3.1.8.6.
See mitigation notes
CVE9.8
NVDPending
Jun 17, 2026 CVE-2026-34888
Bricksforge: Sensitive information exposure
Bricksforge is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is n/a through 3.1.8.4.
3.1.8.5
CVE7.5
NVDPending
Jun 09, 2024 CVE-2024-31244
Bricksforge: A security weakness
Bricksforge is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD7.5
Jun 09, 2024 CVE-2024-31243
Bricksforge: A security weakness
Bricksforge is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Apr 10, 2024 CVE-2024-31242
Bricksforge: A security weakness
Bricksforge is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending