What is CVE-2026-18030?
In BricksForge WordPress plugin versions before 3.1.8.8, the lack of identity verification during password change requests allows unauthenticated attackers to set arbitrary passwords for any user, including administrators, leading to account takeover. Immediate update to the patched version is required to prevent full site compromise.
Azərbaycanca: BricksForge WordPress plugin-inin 3.1.8.8-dən əvvəlki versiyalarında autentifikasiya yoxlanışı olmadığı üçün, icazəsiz şəxslər istənilən istifadəçinin (o cümlədən administratorun) parolunu dəyişərək hesabı ələ keçirə bilər. Bu boşluq saytın tam ələ keçirilməsinə səbəb ola bilər, ona görə dərhal plaqini yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of the BricksForge WordPress plugin are affected by CVE-2026-18030?
All versions before 3.1.8.8 are affected. The security patch is only implemented in version 3.1.8.8 and above.
What can an attacker achieve by exploiting CVE-2026-18030?
An unauthenticated attacker can set arbitrary passwords for any user, including administrators, leading to account takeover and potentially full site compromise.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.