CVE-2026-84814
Subscriber Privilege Escalation in Bricksforge WordPress Plugin (<= 3.1.8.8)
Bricksforge, a companion plugin for the Bricks Builder WordPress theme, mishandles user privilege assignment (CWE-266), allowing accounts at the lowest subscriber tier to escalate to higher-privileged roles. The flaw is reachable over the network, and the assigned CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) indicates the trigger requires no special conditions or user interaction, per the vulnerability description originating from subscriber-level access. An attacker who escalates gains elevated capabilities on the affected WordPress site, with the assigned vector scoring high impact for confidentiality, integrity, and availability (9.8 critical). Any WordPress site running Bricksforge version 3.1.8.8 or earlier is affected. As of now there is no public proof-of-concept, the CVE is not in CISA KEV, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days, so no active exploitation is known.
What to do: Update Bricksforge to a version later than 3.1.8.8 as soon as the vendor publishes a patched release, or deactivate the plugin until a fix is available. As interim mitigation, restrict or disable open subscriber registration and audit existing user accounts for unexpected role changes. There is no public PoC or KEV listing, but treat exposed WordPress sites as priority candidates for patching given the critical 9.8 CVSS score.
| Bricksforge WordPress plugin (companion plugin for Bricks Builder) | <= 3.1.8.8 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-266
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.