Executive brief
Bricksforge, a popular WordPress plugin used for building custom forms and site elements, contains a critical security flaw in its Pro Forms registration feature. This vulnerability allows unauthorized individuals to bypass security checks and register themselves as administrators on the website. If exploited, an attacker could gain full control over the site, potentially leading to data theft, service disruption, or complete site takeover.
Technical details
The Bricksforge plugin for WordPress (up to version 3.1.8.6) is vulnerable to privilege escalation due to improper validation of the 'fieldIds' parameter within the Pro Forms registration action. This flaw allows an attacker to inject arbitrary field IDs into the trusted form-field whitelist. By submitting a specially crafted request to a publicly accessible registration form configured with the User Registration action, an unauthenticated attacker can assign themselves the administrator role. The vulnerability was addressed in version 3.1.8.7.
Affected products
- Bricksforge Bricksforge up to, and including, 3.1.8.6
Timeline
- 2026-07-14: patched: Fixed in version 3.1.8.7
- 2026-07-17: advisory: NVD publication date