← back
CVE-2024-25600criticalobserved exploitationCWE-94

WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability

100Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 10epss 88%
from disclosure to weapon0 days
Published on NVDJun 4
1st PoCFeb 20
metasploitFeb 19
VulnCheckFeb 19
exploitation probability
88%top 1% of all CVEs
observed exploitation
yesVulnCheck
46 public exploit(s)
Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
public PoCs found46
exploitdbwww.exploit-db.com/exploits/52619unverifiedcve_referencegithub.com/K3ysTr0K3R/CVE-2024-25600-EXPLOIT62githubgithub.com/Christbowel/CVE-2024-25600_Nuclei-Template30githubgithub.com/so1icitx/CVE-2024-2560013githubgithub.com/Tornad0007/CVE-2024-25600-Bricks-Builder-plugin-for-WordPress9githubgithub.com/hy011121/CVE-2024-25600-wordpress-Exploit-RCE3githubgithub.com/CerberusMrXi/WP-Bricks-Exploit-CVE-2024-256001githubgithub.com/X-Projetion/WORDPRESS-CVE-2024-25600-EXPLOIT-RCE1githubgithub.com/estebanzarate/CVE-2024-25600-WordPress-Bricks-Builder-RCE-PoC1githubgithub.com/WanLiChangChengWanLiChang/CVE-2024-256000githubgithub.com/KaSooMi0228/CVE-2024-25600-Bricks-Builder-WordPress0githubgithub.com/diamorphine666/CVE-2024-256000githubgithub.com/Sibul-Dan-Glokta/test-task-CVE-2024-256000githubgithub.com/svchostmm/CVE-2024-25600-mass0githubgithub.com/NanoWraith/CVE-2024-256000githubgithub.com/meli0dasH4ck3r/cve-2024-256000githubgithub.com/ivanbg2004/ODH-BricksBuilder-CVE-2024-25600-THM0githubgithub.com/DedsecTeam-BlackHat/Poleposph0githubgithub.com/r0otk3r/CVE-2024-256000githubgithub.com/Anjai7/TryHack3M-Bricks-Heist0githubgithub.com/ranjithxploit/CVE-2024-256000githubgithub.com/h0w1tzxr/TryHack3M-Bricks-Heist0vulncheckvulncheck.com/xdb/6803eccccfebunverifiedvulncheckvulncheck.com/xdb/63d17c42b9efunverifiedvulncheckvulncheck.com/xdb/f6f84a1a36f9unverifiedvulncheckvulncheck.com/xdb/48053e503ee2unverifiedvulncheckvulncheck.com/xdb/9297a3e1bb69unverifiedvulncheckvulncheck.com/xdb/0ba4217465ecunverifiedvulncheckvulncheck.com/xdb/9c0b1ef40266unverifiedvulncheckvulncheck.com/xdb/bf44325d9dd1unverifiedvulncheckvulncheck.com/xdb/035d38d2ed34unverifiedvulncheckvulncheck.com/xdb/f3a02f4301faunverifiedvulncheckvulncheck.com/xdb/93afbea08380unverifiedvulncheckvulncheck.com/xdb/f8c55bc3fe8eunverifiedvulncheckvulncheck.com/xdb/75346e4543bdunverifiedcve_referencegithub.com/Chocapikk/CVE-2024-25600unverifiedvulncheckvulncheck.com/xdb/18041a4481d0unverifiedvulncheckvulncheck.com/xdb/16b1ebadf0c8unverifiedvulncheckvulncheck.com/xdb/bd8997f902e9unverifiedvulncheckvulncheck.com/xdb/fe8e65815213unverifiedvulncheckvulncheck.com/xdb/b88a09ceb847unverifiedvulncheckvulncheck.com/xdb/d461f5e95852unverifiedvulncheckvulncheck.com/xdb/bb8a84b010c0unverifiedvulncheckvulncheck.com/xdb/430d73cc78f5unverifiedvulncheckvulncheck.com/xdb/b362ec702b49unverifiedvulncheckvulncheck.com/xdb/274dd56fb1c4unverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.