Attackers are planting web shells through Bricksforge forms — update WordPress sites built on Bricks today

By George Bailey   Published: 10/09/26   3 min read

If your marketing site or a client site is built with Bricks Builder, check for one add-on today. Bricksforge, an add-on for Bricks, has a form-upload bug that lets anyone plant PHP code on the server without logging in. Patchstack saw attacks start at 5:47 PM ET on October 7.

The contact form was fine. The file it accepted was a web shell.

What happened

Patchstack disclosed CVE-2026-85097 (CVSS 10.0) on October 8. Bricksforge checks a file’s type on upload but trusts the metadata the browser sends when the form is submitted. An attacker uploads a GIF that is also valid PHP, then submits the form with a destination URL ending in .php, and the plugin writes the file there. All versions up to 3.1.8.9 are affected. 3.1.8.10 fixes it.

Patchstack recorded 63 source IPs. In one cluster, 44 IPs sent 56 identical requests within seconds. Others cycled through .phtml, .php7, mixed case and URL-encoded extensions to get past filters.

Why it matters

A web shell on a WordPress server means defaced pages, SEO spam, stolen customer form data and a foothold on whatever else that host can reach. Automated campaigns like this one hit every site they can find, not just interesting ones.

What to do first

Forward this

For whoever manages our WordPress sites (or our agency): any site using the Bricksforge add-on for Bricks Builder needs version 3.1.8.10 today. It’s being exploited to upload web shells without a login. Please also check the uploads folder for stray PHP files.

Details

Hunt / verify

Slack paste: Bricksforge (Bricks Builder add-on) CVE-2026-85097, CVSS 10, exploited since Oct 7 5:47 PM ET: unauthenticated file upload → PHP web shell. Update to 3.1.8.10, block form_submit + temporaryFileUploads at the WAF, hunt for PHP in /wp-content/uploads/ (login_admin_*.php).

Sources

George Bailey

George Bailey is the byline of the CyberExperts editorial desk, the team behind the CyberExperts Daily Brief. The desk covers vulnerabilities, breaches and security news from vendor advisories, CISA alerts and other primary sources, and links those sources in every story. Questions or corrections: [email protected].