WordPress agencies live on plugin risk. This week the risk has a name: CVE-2026-85097 in Bricksforge, a Bricks Builder extension. Patchstack's October 8, 2026 write-up rates it CVSS 10.0: unauthenticated arbitrary file upload leading to remote code execution for versions up to and including 3.1.8.9 , fixed in 3.1.8.10 . Telemetry showed active exploitation attempts beginning around October 7, 2026, 21:47 UTC . If you maintain client sites on Bricks + Bricksforge, this is a same-day fleet operation.
How the exploit works (enough to hunt it)
Bricksforge validates MIME type on first upload, then later trusts client-supplied metadata in temporaryFileUploads — notably the url field — during form submit. Attackers request a nonce from the unauthenticated bricksforge_regenerate_nonce AJAX endpoint, upload a GIF/PHP polyglot that passes the image check, then submit a form where the file path points at the image but the URL ends in a PHP extension. The plugin places contents at the PHP location. Most observed traffic hit POST /wp-json/bricksforge/v1/form_submit ; some used admin-ajax.php with bricksforge_form_submit .
Agency patch plan (run in order)
1. Inventory. Query every managed site for Bricksforge version. Anything ≤3.1.8.9 is vulnerable. 2. Patch. Update to 3.1.8.10 or later immediately. If a site cannot update yet, deploy a WAF/mitigation rule (Patchstack RapidMitigate is cited by the researchers) as a bridge measured in hours. 3. Hunt IoCs. Search logs for temporaryFileUploads , image paths paired with PHP destination URLs, bricksforge_regenerate_nonce followed by uploads, and unexpected PHP under /wp-content/uploads/bricksforge/tmp/ or names like login_admin_*.php . 4. Assume breach when indicators hit. Take the site offline if needed, rotate all credentials (WordPress users, DB, hosts, SMTP, payment keys), replace core/plugin/theme files from known-good packages, and rebuild the host if webshells are confirmed. 5. Client communication. Send a factual note: CVE, versions, patch status, whether IoCs were found, and what you need from them (DNS/host access). 6. Hardening follow-up. Disable unused form endpoints, restrict PHP execution in uploads directories, keep auto-updates or a weekly patch window, and track plugin CVEs in your ops checklist.
# Fleet grep examples (adjust to your WP-CLI / inventory tool)
wp plugin list --name=bricksforge --field=version
# Log hunt signatures
rg -n "temporaryFileUploads|bricksforge_regenerate_nonce|bricksforge/v1/form_submit" /var/log/nginx/
# Uploads PHP unexpectedly
find wp-content/uploads -type f \( -name '*.php' -o -name '*.phtml' -o -name 'login_admin_*.php' \)Why agencies get blamed — and how to avoid it
Clients do not distinguish "plugin vendor bug" from "agency negligence" when a site serves malware. Your differentiator is speed: inventory scripts, patch SLAs, and IoC playbooks prepared before the next CVE. Bricksforge will not be the last critical form-upload bug in the WordPress ecosystem.
Founder takeaway
Upgrade Bricksforge to 3.1.8.10+ now, hunt for polyglot upload IoCs on every client, treat positive hits as incidents, and tell clients clearly what you found. Then turn this week's fire drill into a standing plugin CVE response process.
Fleet tooling you should build this month
If you manage more than a handful of WordPress sites, manual SSH updates do not scale under active exploitation. Stand up (or buy) inventory that reports plugin versions daily, a one-click or scripted update path for critical CVEs, and centralized log search for the IoC strings in Patchstack's write-up. Keep a pre-approved maintenance window template so client emails are not written from scratch at midnight. Also review whether Bricksforge form endpoints need to be internet-open on every site. Marketing microsites that never use advanced forms should not expose unnecessary AJAX/REST actions. Reducing attack surface beats relying solely on vendors to patch quickly.
After the fire drill, schedule a blameless review: time from public exploitation signal to 100% patched, sites with confirmed IoCs, and process gaps. Share a sanitized version with clients who ask how you handle plugin CVEs — it becomes a retention asset.
Operationally, treat this topic as a named owner problem: someone updates the runbook, someone verifies the deadline or launch assumptions against primary sources, and someone reports status in the weekly product meeting. Ambiguity is what turns a manageable change into a scramble. Write down the decision, the date you will re-check sources, and the customer-facing language you will use if asked before the next milestone.
Operationally, treat this topic as a named owner problem: someone updates the runbook, someone verifies the deadline or launch assumptions against primary sources, and someone reports status in the weekly product meeting. Ambiguity is what turns a manageable change into a scramble. Write down the decision, the date you will re-check sources, and the customer-facing language you will use if asked before the next milestone.
Operationally, treat this topic as a named owner problem: someone updates the runbook, someone verifies the deadline or launch assumptions against primary sources, and someone reports status in the weekly product meeting. Ambiguity is what turns a manageable change into a scramble. Write down the decision, the date you will re-check sources, and the customer-facing language you will use if asked before the next milestone.
Operationally, treat this topic as a named owner problem: someone updates the runbook, someone verifies the deadline or launch assumptions against primary sources, and someone reports status in the weekly product meeting. Ambiguity is what turns a manageable change into a scramble. Write down the decision, the date you will re-check sources, and the customer-facing language you will use if asked before the next milestone.
Operationally, treat this topic as a named owner problem: someone updates the runbook, someone verifies the deadline or launch assumptions against primary sources, and someone reports status in the weekly product meeting. Ambiguity is what turns a manageable change into a scramble. Write down the decision, the date you will re-check sources, and the customer-facing language you will use if asked before the next milestone.




