NA

CVE-2024-25600

Vulnerability Summary

This Metasploit module exploits an unauthenticated remote code execution vulnerability in the Bricks Builder Theme versions 1.9.6 and below for WordPress. The vulnerability allows malicious users to execute arbitrary PHP code by leveraging a nonce leakage to bypass authentication and exploit the eval() function usage within the theme. Successful exploitation allows for full control of the affected WordPress site. It is recommended to upgrade to version 1.9.6.1 or higher.

Vulnerability Trend

Vendor Advisories

Check Point Reference: CPAI-2024-0070 Date Published: 23 Feb 2024 Severity: Critical ...

Exploits

This Metasploit module exploits an unauthenticated remote code execution vulnerability in the Bricks Builder Theme versions 196 and below for WordPress The vulnerability allows attackers to execute arbitrary PHP code by leveraging a nonce leakage to bypass authentication and exploit the eval() function usage within the theme Successful exploita ...

Github Repositories

A PoC exploit for CVE-2024-25600 - WordPress Bricks Builder Remote Code Execution (RCE)

CVE-2024-25600 - WordPress Bricks Builder Remote Code Execution (RCE) 🌐 The Bricks theme for WordPress has been identified as vulnerable to a critical security flaw known as CVE-2024-25600 This vulnerability affects all versions up to, and including, 196 of the Bricks Builder plugin It poses a significant risk as it allows unauthenticated attackers to execute arbitrary c

Unauthenticated Remote Code Execution – Bricks <= 1.9.6

CVE-2024-25600 Exploit Tool πŸš€ Description πŸ“ This tool πŸ› οΈ is designed to exploit the CVE-2024-25600 vulnerability πŸ•³οΈ found in the Bricks Builder plugin for WordPress The vulnerability allows for unauthenticated remote code execution on affected websites πŸ’» The tool automates the exploitation process by retrieving nonces and sending specially crafted requests

Nuclei template and information about the POC for CVE-2024-25600

CVE-2024-25600_Nuclei-Template Nuclei template and information about the POC for CVE-2024-25600 Description πŸ“ The Bricks theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 196 This makes it possible for unauthenticated attackers to execute code on the server This template πŸ› οΈ is designed to detect the CVE-2024-25600 vulne

This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress. The vulnerability allows for unauthenticated remote code execution on affected websites. The tool automates the exploitation process by retrieving nonces and sending specially crafted requests to execute arbitrary commands.

CVE-2024-25600 Exploit Tool πŸš€ Description πŸ“ This tool πŸ› οΈ is designed to exploit the CVE-2024-25600 vulnerability πŸ•³οΈ found in the Bricks Builder plugin for WordPress The vulnerability allows for unauthenticated remote code execution on affected websites πŸ’» The tool automates the exploitation process by retrieving nonces and sending specially crafted requests

This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress. The vulnerability allows for unauthenticated remote code execution on affected websites. The tool automates the exploitation process by retrieving nonces and sending specially crafted requests to execute arbitrary commands.

CVE-2024-25600-Bricks-Builder-plugin-for-WordPress Before anything, this it's not my tool, the original one it's from @Tornad0007 This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress The vulnerability allows for unauthenticated remote code execution on affected websites The tool automates the exploitation

This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress. The vulnerability allows for unauthenticated remote code execution on affected websites. The tool automates the exploitation process by retrieving nonces and sending specially crafted requests to execute arbitrary commands.

CVE-2024-25600-Bricks-Builder-plugin-for-WordPress Before anything, this it's not my tool, the original one it's from @Tornad0007 This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress The vulnerability allows for unauthenticated remote code execution on affected websites The tool automates the exploitation

WORDPRESS-CVE-2024-25600-EXPLOIT-RCE - WordPress Bricks Builder Remote Code Execution (RCE)

WORDPRESS-CVE-2024-25600-EXPLOIT-RCE WORDPRESS-CVE-2024-25600-EXPLOIT-RCE - WordPress Bricks Builder Remote Code Execution (RCE)

Recent Articles

Hackers exploit critical RCE flaw in Bricks WordPress site builder
BleepingComputer β€’ Bill Toulas β€’ 19 Feb 2024

Hackers exploit critical RCE flaw in Bricks WordPress site builder By Bill Toulas February 19, 2024 12:55 PM 0 Hackers are actively exploiting a critical remote code execution (RCE) flaw impacting the Brick Builder Theme to run malicious PHP code on vulnerable sites. The Bricks Builder Theme is a premium WordPress theme described as an innovative, community-driven visual site builder. With around 25,000 active installations, the product promotes user friendliness and customization in w...