If your marketing site or a client site is built with Bricks Builder, check for one add-on today. Bricksforge, an add-on for Bricks, has a form-upload bug that lets anyone plant PHP code on the server without logging in. Patchstack saw attacks start at 5:47 PM ET on October 7.
The contact form was fine. The file it accepted was a web shell.
What happened
Patchstack disclosed CVE-2026-85097 (CVSS 10.0) on October 8. Bricksforge checks a file’s type on upload but trusts the metadata the browser sends when the form is submitted. An attacker uploads a GIF that is also valid PHP, then submits the form with a destination URL ending in .php, and the plugin writes the file there. All versions up to 3.1.8.9 are affected. 3.1.8.10 fixes it.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Patchstack recorded 63 source IPs. In one cluster, 44 IPs sent 56 identical requests within seconds. Others cycled through .phtml, .php7, mixed case and URL-encoded extensions to get past filters.
Why it matters
A web shell on a WordPress server means defaced pages, SEO spam, stolen customer form data and a foothold on whatever else that host can reach. Automated campaigns like this one hit every site they can find, not just interesting ones.
What to do first
- Update Bricksforge to 3.1.8.10 or later on every site, including staging and agency-managed sites.
- If you can’t update right away, block
POST /wp-json/bricksforge/v1/form_submitrequests carrying atemporaryFileUploadsparameter at your WAF, or disable Bricksforge forms until you patch. - Look for PHP files in
/wp-content/uploads/, especially/wp-content/uploads/bricksforge/tmp/and files namedlogin_admin_*.php. Uploads folders shouldn’t execute PHP at all. Deny it at the web server.
Forward this
For whoever manages our WordPress sites (or our agency): any site using the Bricksforge add-on for Bricks Builder needs version 3.1.8.10 today. It’s being exploited to upload web shells without a login. Please also check the uploads folder for stray PHP files.
Details
- CVE: CVE-2026-85097, unauthenticated arbitrary file upload leading to remote code execution, CVSS 10.0.
- Affected / fixed: Bricksforge ≤ 3.1.8.9 / 3.1.8.10.
- First exploitation seen: October 7, 2026, 21:47 UTC (5:47 PM ET), per Patchstack telemetry.
- Attack path: unauthenticated
bricksforge_regenerate_nonceAJAX call → GIF/PHP polyglot upload →form_submitwith an imagefilepath and a PHPurl. One request usedadmin-ajax.phpwith actionbricksforge_form_submit. - Most active IPs (Patchstack): 177.75.57.20, 23.97.62.146, 84.247.60.125, 38.154.185.97, 150.109.16.166, 153.75.90.146.
Hunt / verify
- Search access logs for
/wp-json/bricksforge/v1/form_submitrequests since October 7 and for requests to new.phpfiles under/wp-content/uploads/. - Run
find wp-content/uploads -type f \( -iname "*.php*" -o -iname "*.phtml" -o -iname "*.pht*" \)on each site. - Compare admin users and plugin and theme files against a known-good backup if you find anything.
Slack paste: Bricksforge (Bricks Builder add-on) CVE-2026-85097, CVSS 10, exploited since Oct 7 5:47 PM ET: unauthenticated file upload → PHP web shell. Update to 3.1.8.10, block form_submit + temporaryFileUploads at the WAF, hunt for PHP in /wp-content/uploads/ (login_admin_*.php).
Sources
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.