Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-84814: WordPress Bricksforge plugin lets low-level users gain admin rights
CVE-2026-84814 · published today
Summary
The Bricksforge add‑on for WordPress, up through version 3.1.8.8, allows a user with the lowest permission level to elevate their rights to full administrator control. This could let an attacker take over the website, change content, install malicious code, or steal data. Upgrade the plugin to the newest release or uninstall it if you do not need it, and review existing user accounts for any unexpected elevated privileges.
What to do
- Update bricksforge. bricksforge to version 3.1.8.9.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| bricksforge. | bricksforge |
<= 3.1.8.8 Fix: upgrade to 3.1.8.9
|
Original advisory text
WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability
Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
References
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Type
CWE-266Incorrect Privilege Assignment
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Monitor software like this
Free during beta