QID 150812
Date Published: 2024-02-26
QID 150812: WordPress Bricks Theme: Unauthenticated Remote Code Execution Vulnerability (CVE-2024-25600)
Bricks is an advanced, flexible and easy-to-use WordPress theme that allows you to create any type of website.
The Bricks theme for WordPress is vulnerable to Remote Code Execution. This makes it possible for unauthenticated attackers to execute code on the server.
Affected Versions:
WordPress Bricks theme before 1.9.6
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress theme running on the target application.
Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary code on the target system.
Solution
Customers are advised to upgrade to WordPress Bricks theme 1.9.6.1 or latest version to remediate this vulnerability. For more information regarding this vulnerability please refer WordPress Bricks theme.
Vendor References
- Bricks Theme -
bricksbuilder.io/changelog/
CVEs related to QID 150812
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Bricks Theme |
|