Code Injection in Bricks Builder - CVE-2024-25600
Published: February 29, 2024 / Updated: March 31, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation at the "/wp-json/bricks/v1/render_element" endpoint. A remote non-authenticated attacker can send a specially crafted HTTP request to the website and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2024-25600
Links to Public Exploits and PoC-codes
- Exploit #11267 - CVE-2024-25600 (March 31, 2025)
- Exploit #10772 - 0BL1V10N-CVE-2024-25600-Bricks-Builder-plugin-for-WordPress (0BL1V10N's CVE-2024-25600 for Bricks Builder (TryHackMe) plugin for WordPress exploit) (October 25, 2024)
- Exploit #10429 - CVE-2024-25600 (August 23, 2024)
- Exploit #10075 - CVE-2024-25600-wordpress-Exploit-RCE (June 21, 2024)
- Exploit #9926 - CVE-2024-25600 (June 7, 2024)
- Exploit #9843 - CVE-2024-25600-mass (May 23, 2024)
- Exploit #9812 - CVE-2024-25600_Nuclei-Template (May 13, 2024)
- Exploit #9735 - CVE-2024-25600-EXPLOIT (April 19, 2024)
- Exploit #9724 - 0BL1V10N-CVE-2024-25600-Bricks-Builder-plugin-for-WordPress (0BL1V10N's CVE-2024-25600 for Bricks Builder (TryHackMe) plugin for WordPress exploit) (April 19, 2024)
- Exploit #9655 - Unauthenticated RCE in Bricks Builder Theme (March 26, 2024)
- Exploit #9580 - CVE-2024-25600-Bricks-Builder-plugin-for-WordPress (February 29, 2024)