WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 10epss 88%
from disclosure to weapon0 days
Published on NVDJun 4
1st PoCFeb 20
metasploitFeb 19
VulnCheckFeb 19
exploitation probability
88%top 1% of all CVEs
observed exploitation
yesVulnCheck
46 public exploit(s)
Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Codeer Limited · Bricks Builderpublic PoCs found — 46
exploitdbwww.exploit-db.com/exploits/52619unverifiedcve_referencegithub.com/K3ysTr0K3R/CVE-2024-25600-EXPLOIT★ 62githubgithub.com/Christbowel/CVE-2024-25600_Nuclei-Template★ 30githubgithub.com/so1icitx/CVE-2024-25600★ 13githubgithub.com/Tornad0007/CVE-2024-25600-Bricks-Builder-plugin-for-WordPress★ 9githubgithub.com/hy011121/CVE-2024-25600-wordpress-Exploit-RCE★ 3githubgithub.com/CerberusMrXi/WP-Bricks-Exploit-CVE-2024-25600★ 1githubgithub.com/X-Projetion/WORDPRESS-CVE-2024-25600-EXPLOIT-RCE★ 1githubgithub.com/estebanzarate/CVE-2024-25600-WordPress-Bricks-Builder-RCE-PoC★ 1githubgithub.com/WanLiChangChengWanLiChang/CVE-2024-25600★ 0githubgithub.com/KaSooMi0228/CVE-2024-25600-Bricks-Builder-WordPress★ 0githubgithub.com/diamorphine666/CVE-2024-25600★ 0githubgithub.com/Sibul-Dan-Glokta/test-task-CVE-2024-25600★ 0githubgithub.com/svchostmm/CVE-2024-25600-mass★ 0githubgithub.com/NanoWraith/CVE-2024-25600★ 0githubgithub.com/meli0dasH4ck3r/cve-2024-25600★ 0githubgithub.com/ivanbg2004/ODH-BricksBuilder-CVE-2024-25600-THM★ 0githubgithub.com/DedsecTeam-BlackHat/Poleposph★ 0githubgithub.com/r0otk3r/CVE-2024-25600★ 0githubgithub.com/Anjai7/TryHack3M-Bricks-Heist★ 0githubgithub.com/ranjithxploit/CVE-2024-25600★ 0githubgithub.com/h0w1tzxr/TryHack3M-Bricks-Heist★ 0vulncheckvulncheck.com/xdb/6803eccccfebunverifiedvulncheckvulncheck.com/xdb/63d17c42b9efunverifiedvulncheckvulncheck.com/xdb/f6f84a1a36f9unverifiedvulncheckvulncheck.com/xdb/48053e503ee2unverifiedvulncheckvulncheck.com/xdb/9297a3e1bb69unverifiedvulncheckvulncheck.com/xdb/0ba4217465ecunverifiedvulncheckvulncheck.com/xdb/9c0b1ef40266unverifiedvulncheckvulncheck.com/xdb/bf44325d9dd1unverifiedvulncheckvulncheck.com/xdb/035d38d2ed34unverifiedvulncheckvulncheck.com/xdb/f3a02f4301faunverifiedvulncheckvulncheck.com/xdb/93afbea08380unverifiedvulncheckvulncheck.com/xdb/f8c55bc3fe8eunverifiedvulncheckvulncheck.com/xdb/75346e4543bdunverifiedcve_referencegithub.com/Chocapikk/CVE-2024-25600unverifiedvulncheckvulncheck.com/xdb/18041a4481d0unverifiedvulncheckvulncheck.com/xdb/16b1ebadf0c8unverifiedvulncheckvulncheck.com/xdb/bd8997f902e9unverifiedvulncheckvulncheck.com/xdb/fe8e65815213unverifiedvulncheckvulncheck.com/xdb/b88a09ceb847unverifiedvulncheckvulncheck.com/xdb/d461f5e95852unverifiedvulncheckvulncheck.com/xdb/bb8a84b010c0unverifiedvulncheckvulncheck.com/xdb/430d73cc78f5unverifiedvulncheckvulncheck.com/xdb/b362ec702b49unverifiedvulncheckvulncheck.com/xdb/274dd56fb1c4unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/Chocapikk/CVE-2024-25600https://github.com/K3ysTr0K3R/CVE-2024-25600-EXPLOIThttps://patchstack.com/articles/critical-rce-patched-in-bricks-builder-theme?_s_id=cvehttps://patchstack.com/database/vulnerability/bricks/wordpress-bricks-theme-1-9-6-unauthenticated-remote-code-execution-rce-vulnerability?_s_id=cvehttps://snicco.io/vulnerability-disclosure/bricks/unauthenticated-rce-in-bricks-1-9-6