Threat Advisory

Bricks WordPress Theme Vulnerability Allows Remote PHP Code Execution

Threat: Vulnerability
Threat Actor Type: NA
Targeted Region: NA
Threat Actor Region: NA
Targeted Sector: NA
Criticality: High
[subscribe_to_unlock_form]

Summary:

A critical security vulnerability in the popular WordPress Bricks theme has been discovered and is currently under active exploitation. This flaw, tracked as CVE-2024-25600, has a high CVSS score of 9.8, making it a severe threat to WordPress sites that use the Bricks theme. This vulnerability enables unauthenticated attackers to remotely execute arbitrary PHP code on affected WordPress installations. The vulnerability is present in all versions of the Bricks theme up to and including version 1.9.6. which was released on just days after it was reported by WordPress security provider. The vulnerability is rooted in the prepare_query_vars_from_settings() function of the Bricks theme. It occurs due to the improper use of nonce tokens for verifying permissions, which can be publicly accessed on the frontend of a WordPress site. This flaw enables attackers to execute arbitrary commands, effectively taking control of the targeted site. A WordPress security company, has detected more than three dozen attack attempts exploiting this vulnerability. The attacks started on one day after the flaw was publicly disclosed. The attackers appear to be targeting a significant number of WordPress sites, with an estimated 25,000 active installations of the Bricks theme.[/subscribe_to_unlock_form]

Summary:

A critical security vulnerability in the popular WordPress Bricks theme has been discovered and is currently under active exploitation. This flaw, tracked as CVE-2024-25600, has a high CVSS score of 9.8, making it a severe threat to WordPress sites that use the Bricks theme. This vulnerability enables unauthenticated attackers to remotely execute arbitrary PHP code on affected WordPress installations. The vulnerability is present in all versions of the Bricks theme up to and including version 1.9.6. which was released on just days after it was reported by WordPress security provider. The vulnerability is rooted in the prepare_query_vars_from_settings() function of the Bricks theme. It occurs due to the improper use of nonce tokens for verifying permissions, which can be publicly accessed on the frontend of a WordPress site. This flaw enables attackers to execute arbitrary commands, effectively taking control of the targeted site. A WordPress security company, has detected more than three dozen attack attempts exploiting this vulnerability. The attacks started on one day after the flaw was publicly disclosed. The attackers appear to be targeting a significant number of WordPress sites, with an estimated 25,000 active installations of the Bricks theme.[emaillocker id="1283"]

Recommendations:

  • We strongly recommend you update WordPress Bricks theme version to 1.9.6.1 .

References:

The following reports contain further technical details:

https://thehackernews.com/2024/02/wordpress-bricks-theme-under-active.html

[/emaillocker]
crossmenu