First published: Tue Jun 04 2024(Updated: )
Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bricks Builder | <=1.9.6 | |
WordPress Bricks Theme | <=1.9.6 |
Update to 1.9.6.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25600 is classified as a critical vulnerability due to its potential for remote code execution.
CVE-2024-25600 affects Bricks Builder and WordPress Bricks Theme versions up to and including 1.9.6.
To fix CVE-2024-25600, update Bricks Builder or WordPress Bricks Theme to a version that is not vulnerable.
CVE-2024-25600 is categorized as a code injection vulnerability, allowing unauthorized code execution.
Yes, CVE-2024-25600 can be exploited remotely without authentication.