漏洞描述
Bricks Builder is a popular WordPress development theme with approximately 25,000 active installations. It provides an intuitive drag-and-drop interface for designing and building WordPress websites. Bricks <= 1.9.6 is vulnerable to unauthenticated remote code execution (RCE) which means that anybody can run arbitrary commands and take over the site/server. This can lead to various malicious activities
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
cve.mitre.orghttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-25600↗wpscan.comhttps://wpscan.com/vulnerability/afea4f8c-4d45-4cc0-8eb7-6fa6748158bd/↗snicco.iohttps://snicco.io/vulnerability-disclosure/bricks/unauthenticated-rce-in-bricks-1-9-6↗github.comhttps://github.com/Chocapikk/CVE-2024-25600↗