AI analysis
The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload (CWE-434) in versions up to and including 3.1.8.9 because an attacker-controlled URL in the temporaryFileUploads parameter is not sufficiently validated during form submission. An unauthenticated attacker can cause a file that passed temporary upload checks to be referenced with a PHP extension and executed by the server. Successful exploitation allows arbitrary PHP code execution and can fully compromise the site (confidentiality, integrity, and availability), with a CVSS 3.1 score of 9.8. WordPress sites running Bricksforge 3.1.8.9 or earlier are affected. No public proof of concept is known, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Update Bricksforge to a release newer than 3.1.8.9 as soon as the vendor publishes a fix; the advisory data does not name a patched version. Until then, deactivate the plugin or otherwise block unauthenticated access to its form handling, and review the temporary and public upload directories for unexpected PHP files.
Affected
| Bricksforge | up to and including 3.1.8.9 |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a GIF/PHP polyglot file to the temporary upload directory where MIME type validation is correctly performed. Subsequently, the attacker can submit a form with a crafted 'temporaryFileUploads' parameter where the server-side file path points to the validated GIF file, but the attacker-controlled url field ends with a .php extension. This makes it possible for unauthenticated attackers to upload and execute arbitrary PHP code on the server.