Authorization Bypass in BricksForge WordPress Plugin Affects User Accounts
CVE-2026-18030
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 10 August 2026
Badges
What is CVE-2026-18030?
The BricksForge WordPress plugin, versions prior to 3.1.8.8, is vulnerable to an unauthorized password change due to insufficient verification of the requester's identity. This flaw enables unauthenticated attackers to manipulate password reset actions, potentially gaining control over user accounts, including those of administrators. The risk is exacerbated as the server-side current-password verification is disabled by default, leaving installations exposed to exploitation if the action is triggered.
Affected Version(s)
BricksForge 0 < 3.1.8.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved