Vulnerability Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/Chocapikk/CVE-2024-25600
- https://github.com/K3ysTr0K3R/CVE-2024-25600-EXPLOIT
- https://patchstack.com/articles/critical-rce-patched-in-bricks-builder-theme?_s_
- https://patchstack.com/database/vulnerability/bricks/wordpress-bricks-theme-1-9-
- https://snicco.io/vulnerability-disclosure/bricks/unauthenticated-rce-in-bricks-
- https://github.com/Chocapikk/CVE-2024-25600
- https://github.com/K3ysTr0K3R/CVE-2024-25600-EXPLOIT
- https://patchstack.com/articles/critical-rce-patched-in-bricks-builder-theme?_s_
- https://patchstack.com/database/vulnerability/bricks/wordpress-bricks-theme-1-9-
- https://snicco.io/vulnerability-disclosure/bricks/unauthenticated-rce-in-bricks-
FAQ
What is CVE-2024-25600?
CVE-2024-25600 is a vulnerability with a CVSS score of 10.0 (CRITICAL). Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.
How severe is CVE-2024-25600?
CVE-2024-25600 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-25600?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.