Bricksforge is a niche WordPress plugin vendor with a focused product footprint centered on its Bricksforge page-building plugin. The observed vulnerability signal concentrates on missing authorization issues, reflecting the access-control and permission-validation demands of a plugin operating within the WordPress ecosystem. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bricksforge over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-14956CRITICAL The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds paramet | Jul 17, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-34888HIGH Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions. | Jun 17, 2026 | 7.5 | 26 | NO | NO |
CVE-2024-31244HIGH Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. | Jun 9, 2024 | 7.5 | 25 | NO | NO |
CVE-2024-31243HIGH Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. | Jun 9, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-31242MEDIUM Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. | Apr 10, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bricksforge.
Media articles that mention a CVE ID that affects a product developed by Bricksforge — matched by CVE ID, not by vendor name.