bricksbuilder.io
https://bricksbuilder.io/ CVE-2022-3401
HIGH
Record summary
CVE-2022-3401 has a selected CVSS score of 8.8 (high).
Description
The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include executable code blocks in website content in versions 1.2 to 1.5.3. This, combined with the missing authorization vulnerability (CVE-2022-3400), makes it possible for authenticated attackers with minimal permissions, such as a subscriber, can edit any page, post, or template on the vulnerable WordPress website and inject a code execution block that can be used to achieve remote code execution.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 1.2 to ≤ 1.5.3 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-3401 wordfence.com
https://www.wordfence.com/vulnerability-advisories-continued