Bricksforge
cpe:2.3:a:bricksforge:bricksforge:*:*:*:*:wordpress:*:*
- <= 3.1.8.6
A privilege escalation vulnerability has been identified in the Bricksforge plugin for WordPress, affecting all versions through 3.1.8.6. The issue arises from inadequate validation of the fieldIds parameter in the Pro Forms registration action. This flaw allows unauthenticated attackers to manipulate field IDs and add them to a trusted form-field whitelist. Exploitation of this vulnerability enables attackers to register a new administrator account by sending a crafted request to a publicly accessible Bricksforge Pro Forms registration form. Successful exploitation requires the site to have a public Bricksforge Pro Forms element configured with the User Registration action.
Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling attackers to gain administrative access on the affected WordPress site.
Users are advised to update the Bricksforge WordPress plugin to version 3.1.8.7 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.