CVE-2024-25600: WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Codeer Limited Bricks Builder (WordPress Bricks Theme)to a version that resolves this vulnerability.Fixed in 1.9.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25600?
CVE-2024-25600 is classified as a critical vulnerability due to its potential for remote code execution.
What systems are affected by CVE-2024-25600?
CVE-2024-25600 affects Bricks Builder and WordPress Bricks Theme versions up to and including 1.9.6.
How do I fix CVE-2024-25600?
To fix CVE-2024-25600, update Bricks Builder or WordPress Bricks Theme to a version that is not vulnerable.
What type of vulnerability is CVE-2024-25600?
CVE-2024-25600 is categorized as a code injection vulnerability, allowing unauthorized code execution.
Can CVE-2024-25600 be exploited remotely?
Yes, CVE-2024-25600 can be exploited remotely without authentication.