Critical Privilege Escalation Flaw Found in Bricksforge WordPress Plugin
A critical vulnerability in the Bricksforge WordPress plugin allows unauthenticated attackers to create unauthorized administrator accounts.
The Bricksforge plugin for WordPress, in all versions up to and including 3.1.8.6, is affected by a critical privilege escalation vulnerability tracked as CVE-2026-14956. The flaw stems from improper validation of the fieldIds parameter within the Pro Forms registration action, which permits the injection of attacker-supplied field IDs into the trusted form-field whitelist.
This vulnerability carries a CVSS score of 9.8 and poses a significant security risk. By submitting a crafted request to a publicly accessible Bricksforge Pro Forms element configured with the User Registration action, an unauthenticated attacker can register a new account with administrative privileges.
Site administrators using the Bricksforge plugin are advised to verify their Pro Forms configurations and monitor for updates to address this security deficiency.
Sources
- GitHub Security Advisories Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.