CVE-2026-14956
The Bricksforge plugin for WordPress contains a privilege‑escalation flaw in versions up to 3.1.8.6 that lets unauthenticated attackers add administrator accounts by manipulating the fieldIds parameter in a public Pro Forms registration form. The vulnerability stems from improper validation of user‑supplied field IDs, which can be added to a trusted whitelist. Exploitation is possible only when a site has a publicly accessible Bricksforge Pro Forms element configured with the User Registration action.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
WordPress sites using the Bricksforge plugin version 3.1.8.6 or earlier with a public Pro Forms registration form that has the User Registration action enabled.
Real-world impact
An attacker could create an administrator account without authentication, gaining full control of the WordPress site.
Why this severity
The CVSS v3.1 base score is 9.8 (Critical) because the attack is network‑based, requires low complexity, no privileges, no user interaction, and can lead to complete compromise of confidentiality, integrity, and availability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 17, 2026 · 17d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.