- Patchstack reports exploitation attempts against CVE-2026-85097, a Bricksforge flaw that lets unauthenticated attackers upload and run PHP code. Versions up to 3.1.8.9 are affected.
- The plugin checked a file when it arrived, then trusted the details sent with the later form submission. That gap is the flaw.
- Update to Bricksforge 3.1.8.10, then check upload folders and logs for stray PHP files.
Picture a building where a guard checks your ID at the front door. Later, you hand a clerk a note naming the room you want, and the clerk simply believes it. That is the shape of the flaw Patchstack describes in Bricksforge, a WordPress plugin. The lesson is that checking something once is not the same as keeping it safe.
What Patchstack found
Patchstack, which publishes WordPress security intelligence, reports that CVE-2026-85097 is being targeted in the wild. The flaw lets an unauthenticated visitor upload and run PHP code on a vulnerable site. That is remote code execution. Every release through 3.1.8.9 is vulnerable. Version 3.1.8.10 contains the fix.
Bricksforge extends Bricks Builder, a visual site builder for WordPress. It adds forms, animations and dynamic data features. The earliest attempts in Patchstack's data came at 21:47 UTC on October 7, 2026.
How the attack works
Patchstack says Bricksforge checks a file's type when it is first uploaded. When a form is submitted later, the plugin trusts the file details the visitor's browser sends. One field goes unchecked: the url value nested inside the temporaryFileUploads parameter.
That gives attackers four steps. First, they request a security token from an AJAX endpoint (a background web call) that needs no login. Second, they upload a file that is both a valid image and a carrier for PHP code. It passes the image check. Third, they submit a form that points to that image but names a destination ending in .php. Fourth, the plugin places the file's contents at the PHP location. When the attacker requests that address, the server runs the code.
From there, Patchstack says an attacker can deploy web shells, change site content, read sensitive data and set up lasting access.
Automated, persistent and still probing
Almost all the attempts Patchstack saw hit the Bricksforge REST endpoint for form submission. One used the standard WordPress admin-ajax.php route. Every request carried a crafted temporaryFileUploads parameter.
The telltale sign is a mismatch. The file path points to an image, while the destination points to PHP. Most captured requests showed it.
Attackers are also testing the plugin's filters. Patchstack saw alternative extensions such as .phtml and .php8, mixed-case spellings, and URL-encoded forms. In one cluster, 44 IPs sent 56 identical requests within seconds. In another, three IPs tried 25 variations against the same temporary file.
Patchstack says this points to automation over rotating or distributed infrastructure. It adds that the pattern does not, on its own, identify a single threat actor. It recorded 63 unique source IPs, drawn from datacenters, cloud providers, VPN services and ordinary ISPs.
Why this matters beyond one plugin
The flaw sits in a plugin, not in WordPress itself. A review that looks only at core software would not show this exposure. Each add-on brings its own code, its own checks and its own mistakes.
Patchstack's report does not say how many sites run Bricksforge. It does not say how many were compromised either. The attempts are documented; the number of successful intrusions is unknown.
Patchstack also says its mitigation rule for this CVE was live before the first attack arrived. That is a vendor claim about its own product. The gap that matters is the one between disclosure and your own team installing the fix.
What to ask your team
Start with inventory. Does your team know which sites run Bricksforge, and at which version? Anything at 3.1.8.9 or earlier needs the update to 3.1.8.10.
Then ask about history. If a site ran a vulnerable version unprotected, Patchstack advises reviewing logs and the host itself. On the host, search the upload folders for PHP files that should not exist. Start with the Bricksforge temporary folder under /wp-content/uploads/. Files named login_admin_ followed by a suffix and .php are a specific warning sign. In the logs, look for requests to the form_submit endpoint that include temporaryFileUploads.
Patchstack's first sighting is not proof that nothing came earlier, so do not limit the review to October 7.
Finally, ask how quickly your team can approve and install a plugin update while a flaw is being targeted. The first attempts Patchstack recorded came at 21:47 UTC on October 7. Attackers do not wait for a scheduled change window.
A guard at the door protects little if the clerk inside believes any note. Plugins that validate once and trust later invite this kind of flaw. Your update process has to move faster than the people probing for it.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Patchstack.





