Junglewise Threat Intelligence

CVE-2026-84814: Bricksforge privilege escalation in WordPress plugin

CVE-2026-84814 · Severity: critical · CVSS 9.8 · Published 2026-09-03

Technologies: Bricksforge. Vendors: Bricksforge.

Executive brief

Bricksforge is a popular WordPress plugin for building websites. A critical flaw allows low-privilege subscriber accounts to escalate their permissions and gain full administrative control over a WordPress site. This is dangerous because any user with basic site access—such as a content contributor or shop manager—can become an administrator and compromise the entire site, steal customer data, install malware, or deface the website.

Technical details

This is a privilege escalation vulnerability in the Bricksforge WordPress plugin affecting versions 3.1.8.8 and earlier. A subscriber (low-privilege user) can exploit an authentication or authorization flaw to gain administrator-level access without requiring additional credentials or user interaction. The attack requires only that the attacker already has a valid subscriber account on the target WordPress site. The vulnerability was patched in version 3.1.8.9, released in September 2026. Exploitation is highly likely in the wild given the simplicity of the attack vector and high impact.

Affected products

  • Bricksforge Bricksforge 3.1.8.8 and earlier

Timeline

  • 2026-09-03: disclosed
  • 2026-09-02: patched: Patched in version 3.1.8.9
  • 2026-08-16: other: Vulnerability reported to Patchstack

References

Related threats