CVE-2024-25600

Published Jun 4, 2024

Last updated 10 months ago

CVSS critical 10.0
WordPress
Bricks Builder

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2024-25600 is a Remote Code Execution (RCE) vulnerability affecting the Bricks Builder plugin for WordPress. This vulnerability exists in versions up to and including 1.9.6. The vulnerability stems from improper handling of user input within the Bricks Builder plugin, which allows unauthenticated attackers to inject and execute arbitrary PHP code remotely on the server. Exploitation could lead to full site compromise, data theft, and potential malware distribution. A patch addressing this vulnerability has been released in Bricks Builder plugin version 1.9.6.1 or higher.

Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.
Source
audit@patchstack.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

audit@patchstack.com
CWE-94

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1