Executive brief
Bricksforge, a popular extension for the Bricks Builder on WordPress, is vulnerable to a flaw that allows unauthorized individuals to access sensitive information. This could lead to the exposure of internal system data or user information that is normally protected. An attacker could use this information to launch further, more targeted attacks against the website or its users.
Technical details
A sensitive data exposure vulnerability exists in the Bricksforge plugin for WordPress (versions <= 3.1.8.4) due to improper restriction of sensitive information (CWE-201). An unauthenticated remote attacker can exploit this flaw to access data that should be restricted to administrative or authenticated users. The vulnerability is reachable over the network without user interaction. This exposure can facilitate further exploitation by providing attackers with internal configuration details or other sensitive metadata. The issue is resolved in version 3.1.8.5.
Affected products
- Bricksforge Bricksforge <= 3.1.8.4
Timeline
- 2026-02-20: other: Vulnerability reported by researcher luc
- 2026-04-06: advisory: Initial advisory published by Patchstack
- 2026-06-17: disclosed: CVE published to NVD
- 2026-06-17: patched: Patch confirmed available in version 3.1.8.5