• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
wordpress bricks theme under active attack: critical flaw impacts 25,000+

WordPress Bricks Theme Under Active Attack: Critical Flaw Impacts 25,000+ Sites

You are here: Home / General Cyber Security News / WordPress Bricks Theme Under Active Attack: Critical Flaw Impacts 25,000+ Sites
February 20, 2024

A critical security flaw in the Bricks theme for WordPress is becoming actively exploited by risk actors to operate arbitrary PHP code on inclined installations.

The flaw, tracked as CVE-2024-25600 (CVSS rating: 9.8), allows unauthenticated attackers to accomplish distant code execution. It impacts all variations of the Bricks up to and which include 1.9.6.

It has been dealt with by the theme developers in variation 1.9.6.1 produced on February 13, 2024, simply days immediately after WordPress security company Snicco reported the flaw on February 10.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Though a evidence-of-thought (PoC) exploit has not been introduced, specialized specifics have been introduced by both equally Snicco and Patchstack, noting that the fundamental vulnerable code exists in the prepare_question_vars_from_configurations() functionality.

Specially, it concerns the use of security tokens referred to as “nonces” for verifying permissions, which can then be used to pass arbitrary commands for execution, properly making it possible for a danger actor to seize manage of a targeted internet site.

The nonce worth is publicly available on the frontend of a WordPress website, Patchstack said, adding there are no sufficient purpose checks applied.

Cybersecurity

“Nonces ought to under no circumstances be relied on for authentication, authorization, or access management,” WordPress cautions in its documentation. “Protect your functions employing present_person_can(), and constantly assume nonces can be compromised.”

WordPress security corporation Wordfence explained it detected above three dozen attack makes an attempt exploiting the flaw as of February 19, 2024. Exploitation makes an attempt are said to have commenced on February 14, a working day immediately after public disclosure.

A majority of the attacks are from the adhering to IP addresses –

  • 200.251.23[.]57
  • 92.118.170[.]216
  • 103.187.5[.]128
  • 149.202.55[.]79
  • 5.252.118[.]211
  • 91.108.240[.]52

Bricks is estimated to have all-around 25,000 at present active installations. People of the plugin are suggested to apply the newest patches to mitigate opportunity threats.

Observed this posting fascinating? Observe us on Twitter  and LinkedIn to go through a lot more special written content we article.


Some pieces of this report are sourced from:
thehackernews.com

Previous Post: «iran and hezbollah hackers launch attacks to influence israel hamas narrative Iran and Hezbollah Hackers Launch Attacks to Influence Israel-Hamas Narrative
Next Post: Critical Flaws Found in ConnectWise ScreenConnect Software – Patch Now critical flaws found in connectwise screenconnect software patch now»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.