Bricksforge, an add-on plugin for the Bricks site builder, has a critical flaw that attackers are already using. Patchstack says it first saw exploitation attempts on October 7, 2026, at 21:47 UTC.
What happened
The flaw is tracked as CVE-2026-85097 and scores a perfect 10.0 on the CVSS severity scale. It lets an attacker upload a file to your site without logging in. If that file contains PHP code, the attacker can run it on your server. Security teams call this remote code execution.
It affects Bricksforge version 3.1.8.9 and earlier. The fix is in version 3.1.8.10.
Who is affected
Anyone running Bricksforge 3.1.8.9 or earlier. No account or special setting is needed to attack the site. Patchstack lists the plugin at about 6,000 installs.
What to do
- Update Bricksforge to 3.1.8.10 or later now.
- Look in your uploads folder and the rest of
/wp-content/for PHP files you do not recognize. - Check your Users screen for admin accounts you did not create.
- If you find anything suspicious, treat the site as breached. Remove the files, then reset admin passwords and your WordPress security keys.
Similar upload flaws have been used against other plugins for weeks. Updating after the fact does not remove a backdoor an attacker has already planted.
End of article