The Bricks theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.6.1. This is due to insufficient validation checks placed on the create_autosave AJAX function. This makes it possible for authenticated attackers, with contributor-level access and above, to execute arbitrary PHP code with elevated (administrator-level) privileges. NOTE: Successful exploitation requires (1) the Bricks Builder to be enabled for posts (2) Builder access to be enabled for contributor-level users, and (3) "Code Execution" to be enabled for administrator-level users within the theme's settings.
References
Link | Resource |
---|---|
https://bricksbuilder.io/release/bricks-1-9-7/ | Release Notes |
https://www.wordfence.com/threat-intel/vulnerabilities/id/cb075e85-75fc-4008-8270-4d1064ace29e?source=cve | Third Party Advisory |
Configurations
History
11 Mar 2025, 19:39
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
First Time |
Bricksbuilder
Bricksbuilder bricks |
|
References | () https://bricksbuilder.io/release/bricks-1-9-7/ - Release Notes | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/cb075e85-75fc-4008-8270-4d1064ace29e?source=cve - Third Party Advisory | |
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:bricksbuilder:bricks:*:*:*:*:*:wordpress:*:* |
27 Feb 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-27 06:15
Updated : 2025-03-11 19:39
NVD link : CVE-2024-2297
Mitre link : CVE-2024-2297
CVE.ORG link : CVE-2024-2297
JSON object : View
Products Affected
bricksbuilder
- bricks
CWE