CyberRota Analysis
AI-GeneratedThe Bricksforge plugin for WordPress is vulnerable to privilege escalation, allowing unauthenticated attackers to create new administrator accounts by exploiting improper validation of the fieldIds parameter in the Pro Forms registration action. This critical vulnerability affects all versions up to 3.1.8.6 and poses a significant risk to any WordPress site utilizing the Bricksforge Pro Forms with user registration enabled. WordPress administrators using this plugin should prioritize immediate updates to mitigate potential unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to the trusted form-field whitelist. This makes it possible for unauthenticated attackers to register a new administrator account by submitting a crafted request to a publicly accessible Bricksforge Pro Forms registration form. Successful exploitation requires that the site has a public Bricksforge Pro Forms element configured with the User Registration action.