The NVD has published CVE-2026-85097, a CVSS 9.8 (Critical), network-exploitable vulnerability in the Bricksforge plugin for WordPress. Versions up to and including 3.1.8.9 are vulnerable to unauthenticated arbitrary file upload, and the attack chain ends in remote code execution on the underlying web server. If Bricksforge is installed on any WordPress property you operate — corporate marketing sites, customer portals, staging environments — treat this as an emergency patch event, not a routine update. Unauthenticated file-upload-to-RCE chains in WordPress plugins are among the most reliably mass-exploited vulnerability classes in the ecosystem, and automated scanners begin sweeping for vulnerable endpoints within days of public disclosure.
Technical Analysis
Affected product: Bricksforge plugin for WordPress — all versions up to and including 3.1.8.9.
CVE / Severity: CVE-2026-85097, CVSS 9.8 (Critical), attack vector: NETWORK, no authentication required, no user interaction required.
Root cause: Insufficient validation of the attacker-controlled URL field inside the temporaryFileUploads parameter during form submission. The plugin's temporary upload handling trusts a value the client fully controls, allowing an attacker to relocate a staged file into an attacker-selected, web-accessible location.
Attack chain (defender's view):
- Nonce acquisition. The attacker calls the
bricksforge_regenerate_nonceAJAX endpoint to obtain a valid WordPress nonce. This step requires no credentials — the endpoint issues nonces to anonymous sessions, which is itself a design flaw that enables the rest of the chain. - Polyglot staging. The attacker uploads a GIF/PHP polyglot file to the plugin's temporary upload directory. MIME type validation on the initial upload is performed correctly, which is why a polyglot is required: the file passes as a valid GIF image while carrying an embedded PHP payload (typically in the comment/extension block after the GIF89a magic bytes).
- Path redirection. The attacker submits a form containing a crafted
temporaryFileUploadsparameter. Because the URL field is insufficiently validated, the plugin processes the staged polyglot into an attacker-influenced destination — a web-accessible path where the file is served or executed as PHP. - Code execution. The attacker requests the relocated file over HTTP. The embedded PHP executes under the web server's user context, yielding a webshell and full control of the WordPress installation: database credentials in
wp-config.php, lateral movement into the hosting environment, and persistence via rogue admin accounts or modified theme/plugin files.
Exploitation status: The vulnerability is publicly documented in the NVD. At the time of writing there is no confirmed CISA KEV listing, but the bar to weaponization is low — the exploit requires only three HTTP requests and no authentication. WordPress plugin flaws with this profile are routinely folded into mass-exploitation toolkits within days. Defenders should operate on the assumption that scanning and exploitation attempts are already underway and check both patch status and forensic indicators immediately.
Detection & Response
Detection should focus on three observable layers: (1) web access patterns matching the exploit chain — nonce regeneration followed by upload and form submission, (2) filesystem artifacts — PHP content appearing in upload directories, and (3) post-exploitation behavior — the web server process spawning shells or making outbound connections. On WordPress hosting, the highest-fidelity signal is the presence of executable PHP content inside wp-content/uploads/ or plugin temporary directories; legitimate media workflows never produce that.
---
title: Bricksforge CVE-2026-85097 Exploit Chain - Nonce Regeneration and File Upload
id: 8f2c1a94-3b7e-4d52-9f18-2a6c4e0b7193
status: experimental
description: Detects HTTP requests matching the CVE-2026-85097 exploitation sequence against the WordPress Bricksforge plugin - unauthenticated nonce regeneration via the bricksforge_regenerate_nonce AJAX action or form submissions carrying the temporaryFileUploads parameter.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2026-85097
author: Security Arsenal
date: 2026/04/06
tags:
- attack.initial_access
- attack.t1190
logsource:
category: webserver
product: apache
detection:
selection_nonce:
cs-uri-query|contains: 'bricksforge_regenerate_nonce'
selection_upload:
cs-uri-query|contains: 'temporaryFileUploads'
condition: 1 of selection_*
falsepositives:
- Legitimate Bricksforge form submissions from authenticated site administrators
- Site editors using Bricksforge front-end forms during content updates
level: high
---
title: PHP Webshell Written to WordPress Uploads Directory
id: 3d9e7b16-8c42-4f60-a521-9b4d2e7f0a38
status: experimental
description: Detects creation of PHP files or GIF/PHP polyglot content inside WordPress upload or plugin temporary directories - the primary forensic artifact of CVE-2026-85097 arbitrary file upload exploitation.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2026-85097
author: Security Arsenal
date: 2026/04/06
tags:
- attack.persistence
- attack.t1505.003
logsource:
category: file_event
product: linux
detection:
selection_path:
TargetFilename|contains:
- '/wp-content/uploads/'
- '/wp-content/uploads/bricksforge/'
- '/wp-content/plugins/bricksforge/'
selection_ext:
TargetFilename|endswith:
- '.php'
- '.phtml'
- '.php5'
- '.php7'
- '.phar'
condition: selection_path and selection_ext
falsepositives:
- Plugin or theme updates writing PHP to plugin directories (restrict to uploads paths where possible)
- Developers deploying code via CI/CD pipelines to staging environments
level: critical
---
title: Web Server Process Spawning Shell - Post-Exploitation Indicator
id: 6b1a4d87-2e93-4c41-bf65-7a0c9d3e5812
status: experimental
description: Detects the web server user or PHP-FPM process spawning command shells - consistent with interactive webshell activity following successful exploitation of a WordPress file upload vulnerability such as CVE-2026-85097.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2026-85097
- https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.execution
- attack.t1059.004
- attack.t1505.003
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- '/php-fpm'
- '/apache2'
- '/httpd'
- '/nginx'
selection_user:
User|contains:
- 'www-data'
- 'apache'
- 'nginx'
selection_child:
Image|endswith:
- '/sh'
- '/bash'
- '/dash'
- '/zsh'
- '/python'
- '/python3'
- '/perl'
- '/nc'
- '/ncat'
- '/curl'
- '/wget'
condition: (selection_parent or selection_user) and selection_child
falsepositives:
- Legitimate WordPress cron or backup plugins invoking shell utilities (rare and reviewable)
- Hosting panel management agents running as the web user
level: high
// Hunt for CVE-2026-85097 exploitation attempts against Bricksforge in web/proxy logs ingested into Sentinel
// Covers nonce regeneration, temporaryFileUploads form submissions, and requests for PHP files under uploads paths
let timeframe = 14d;
CommonSecurityLog
| where TimeGenerated > ago(timeframe)
| where RequestURL has_any ("bricksforge_regenerate_nonce", "temporaryFileUploads")
or (RequestURL has "wp-content/uploads/" and RequestURL has_any (".php", ".phtml", ".phar"))
| project TimeGenerated, SourceIP, SourcePort, RequestMethod, RequestURL, RequestContext, DestinationHostName, DeviceAction
| summarize AttemptCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, RequestURL
| order by AttemptCount desc;
-- CVE-2026-85097: Hunt for PHP/polyglot payloads staged in WordPress upload and plugin temp directories
-- Flags PHP files and GIF files containing embedded PHP tags under web content paths
LET paths = glob(glob="/var/www/**/wp-content/uploads/**/*.php", accessor="file") +
glob(glob="/var/www/**/wp-content/uploads/**/*.phtml", accessor="file") +
glob(glob="/var/www/**/wp-content/plugins/bricksforge/**/*.gif", accessor="file")
SELECT FullPath, Size, Mtime,
read_file(filename=FullPath, length=4096) AS Head
FROM foreach(row=paths)
WHERE FullPath =~ "\\.(php|phtml)$"
OR Head =~ "<\\?php|\\?php|eval\\("
#!/bin/bash
# CVE-2026-85097 - Bricksforge WordPress plugin verification and hardening
# Run on the WordPress host (adjust WP_ROOT as needed). Requires wp-cli for version checks.
WP_ROOT="/var/www/html"
# 1. Identify the installed Bricksforge version
if command -v wp &>/dev/null; then
wp plugin list --path="$WP_ROOT" --format=table | grep -i bricksforge
VER=$(wp plugin get bricksforge --path="$WP_ROOT" --field=version 2>/dev/null)
echo "[+] Bricksforge version: $VER"
# Flag vulnerable versions (<= 3.1.8.9)
if [ -n "$VER" ] && [ "$(printf '%s\n3.1.8.9\n' "$VER" | sort -V | head -n1)" = "$VER" ]; then
echo "[!] VULNERABLE VERSION DETECTED - update Bricksforge immediately or deactivate:"
echo " wp plugin deactivate bricksforge --path=$WP_ROOT"
fi
else
grep -m1 "Version:" "$WP_ROOT"/wp-content/plugins/bricksforge/bricksforge.php 2>/dev/null
fi
# 2. Sweep for PHP/polyglot webshells planted in uploads and plugin temp paths
echo "[+] Scanning for PHP content under uploads and Bricksforge directories..."
find "$WP_ROOT"/wp-content/uploads "$WP_ROOT"/wp-content/plugins/bricksforge \
-type f \( -name "*.php" -o -name "*.phtml" -o -name "*.phar" \) -ls 2>/dev/null
echo "[+] Scanning image files for embedded PHP tags (polyglots)..."
grep -rIl --include="*.gif" --include="*.jpg" --include="*.png" -e "<?php" -e "<?=" \
"$WP_ROOT"/wp-content/uploads 2>/dev/null
# 3. Block PHP execution in the uploads directory (Apache/.htaccess)
cat > "$WP_ROOT"/wp-content/uploads/.htaccess <<'EOF'
# CVE-2026-85097 hardening - deny PHP execution in uploads
<FilesMatch "\.(php|phtml|phar|php[0-9])$">
Require all denied
</FilesMatch>
php_flag engine off
EOF
echo "[+] Wrote PHP-execution block to wp-content/uploads/.htaccess"
# 4. Audit access logs for exploit-chain indicators
echo "[+] Access log hits for nonce regeneration / temporaryFileUploads (last 14 days):"
grep -hE "bricksforge_regenerate_nonce|temporaryFileUploads" /var/log/apache2/access*.log* /var/log/nginx/access*.log* 2>/dev/null | tail -n 50
Remediation
1. Update Bricksforge immediately. Upgrade to a release newer than 3.1.8.9 as soon as the vendor publishes a fixed build. Check the plugin's changelog and the WordPress plugin repository for the patched version number, and verify the update applied on every site — including staging and forgotten subdomains, which are frequently exploited first because they lag on patching.
2. If a patched release is not yet available, deactivate the plugin. wp plugin deactivate bricksforge removes the attack surface entirely. A broken layout builder is infinitely preferable to a compromised host. Do not attempt to mitigate by firewall rules alone while the vulnerable code path remains reachable.
3. Block PHP execution in upload directories. Enforce this at the web server layer (the .htaccess snippet above for Apache, or an equivalent location block denying .php under /wp-content/uploads/ for Nginx). This is durable defense-in-depth that neutralizes the entire upload-to-RCE class, not just this CVE.
4. Assume breach and hunt. Because exploitation requires no authentication and leaves clear artifacts, run the file-sweep and log-review steps above before and after patching. Any PHP file in wp-content/uploads/, any GIF containing <?php, or any access-log hits on bricksforge_regenerate_nonce from unfamiliar IPs warrant a full IR workup: review wp_users for rogue administrator accounts, diff plugin/theme files against known-good copies, rotate database and wp-config.php credentials, and check for cron or mu-plugins persistence.
5. Reduce anonymous AJAX exposure. Audit which plugin AJAX endpoints are reachable by unauthenticated sessions (admin-ajax.php with nopriv actions). Web application firewall rules restricting bricksforge_regenerate_nonce to authenticated sessions can serve as a temporary compensating control, but treat WAF rules as a seatbelt, not a fix — update the plugin.
6. Operational hygiene. Confirm your WordPress estate inventory actually includes Bricksforge deployments — plugin-level blind spots are how CVSS 9.8s survive for months. Enable automatic plugin updates where change windows allow, and monitor the NVD entry (https://nvd.nist.gov/vuln/detail/CVE-2026-85097) and CISA KEV for escalation to confirmed exploitation.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.