QID 731207
Date Published: 2024-02-28
QID 731207: WordPress Bricks Builder Theme Remote Code Execution (RCE) Vulnerability
Bricks is an advanced, flexible and easy-to-use WordPress theme that allows you to create any type of website.
The Bricks theme for WordPress is vulnerable to Remote Code Execution. This makes it possible for unauthenticated attackers to execute code on the server.
Affected Versions:
WordPress Bricks theme before 1.9.6.1
QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for Bricks Plugin using Blind Elephant Fingerprint technique.
Successful exploitation of this vulnerability could allow an unauthenticated attackers to execute code on the the target system.
Solution
Customers are advised to install Bricks theme 1.9.6.1 or later version to remediate this vulnerability. For more information regarding this vulnerability please refer WordPress Bricks theme.
Vendor References
- WP Bricks Builder Plugin Release Notes -
bricksbuilder.io/changelog
CVEs related to QID 731207
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Bricks Theme |
|