CERT-In Vulnerability Note
CIVN-2024-0057
Remote Code Execution Vulnerability in Bricks Builder for WordPress
Original Issue Date:February 21, 2024
Severity Rating: CRITICAL
Software Affected
- Bricks Builder versions prior to 1.9.6.1
Overview
A vulnerability has been reported in Bricks Builder for WordPress, which could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.
Description
Bricks or Bricks Builder is a visual site builder that allows users to create web pages on WordPress without using code through their drag-and-drop interface. This vulnerability exists in Bricks Builder for WordPress due to an eval function call in the "prepare_query_vars_from_settings" function. An unauthenticated attacker could exploit this vulnerability by executing malicious PHP code on the targeted system. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized control over websites running on an affected version of Bricks.
Note: This vulnerability(CVE-2024-25600) is actively exploited in the wild, and users are advised to apply patches urgently.
Solution
Apply appropriate security updates as mentioned in the below link:
https://wpscan.com/vulnerability/afea4f8c-4d45-4cc0-8eb7-6fa6748158bd/
Vendor Information
WPScan
https://wpscan.com/vulnerability/afea4f8c-4d45-4cc0-8eb7-6fa6748158bd/
References
WPScan
https://wpscan.com/vulnerability/afea4f8c-4d45-4cc0-8eb7-6fa6748158bd/
Wordfence
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/bricks/bricks-196-unauthenticated-remote-code-execution
Bricksbuilder
https://bricksbuilder.io/release/bricks-1-9-6-1/
Snicco
https://snicco.io/vulnerability-disclosure/bricks/unauthenticated-rce-in-bricks-1-9-6
Bleeping Computer
https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-rce-flaw-in-bricks-wordpress-site-builder/
CVE Name
CVE-2024-25600
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|