Authorization Bypass in BricksForge WordPress Plugin Affects User Accounts
CVE-2026-18030
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 10 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-18030?
The BricksForge WordPress plugin, versions prior to 3.1.8.8, is vulnerable to an unauthorized password change due to insufficient verification of the requester's identity. This flaw enables unauthenticated attackers to manipulate password reset actions, potentially gaining control over user accounts, including those of administrators. The risk is exacerbated as the server-side current-password verification is disabled by default, leaving installations exposed to exploitation if the action is triggered.
Affected Version(s)
BricksForge 0 < 3.1.8.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.