Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-14956: Bricksforge <= 3.1.8.6 - Unauthenticated Admin Account Creation via Public Form
CVE-2026-14956
CVE-2026-14956
Summary
A security issue in Bricksforge plugin for WordPress allows attackers to create new admin accounts without a password. This can happen if a public form is configured to allow user registration. To fix this, update the Bricksforge plugin to a version higher than 3.1.8.6.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| bricksforge | bricksforge | <= 3.1.8.6 |
Original title
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro For...
Original description
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to the trusted form-field whitelist. This makes it possible for unauthenticated attackers to register a new administrator account by submitting a crafted request to a publicly accessible Bricksforge Pro Forms registration form. Successful exploitation requires that the site has a public Bricksforge Pro Forms element configured with the User Registration action.
nvd CVSS3.1
9.8
Vulnerability type
CWE-269
Improper Privilege Management
Published: 17 Jul 2026 · Updated: 21 Jul 2026 · First seen: 17 Jul 2026