CVE-2026-18030
8.1BricksForge · BricksForge
The BricksForge WordPress plugin is vulnerable to account takeover because it fails to verify user identity when processing password change requests in specific form configurations.
Executive summary
A critical authentication flaw in the BricksForge WordPress plugin allows unauthenticated attackers to reset passwords for any account, including administrators.
Vulnerability
This is a missing authorization vulnerability where the plugin fails to verify the requester's identity during password change actions. Unauthenticated attackers can leverage this to set arbitrary passwords for existing users.
Business impact
The CVSS score of 8.1 reflects the severe impact of this vulnerability. By allowing an attacker to change the passwords of administrative users, the flaw facilitates a complete compromise of the WordPress site, enabling full administrative control and potential data exfiltration or site defacement.
Remediation
Immediate Action: Update the BricksForge plugin to version 3.1.8.8 or later, as recommended by the vendor.
Proactive Monitoring: Audit user account changes and recent password reset logs for any suspicious activity or unauthorized account modifications.
Compensating Controls: Temporarily disable any forms utilizing the plugin's password reset functionality until the update can be applied.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the ability for an attacker to gain administrative access without credentials, this vulnerability must be treated with extreme urgency. Administrators should apply the update to version 3.1.8.8 immediately to eliminate the risk of account takeover.