CVE-2024-25600

CRITICAL EXPLOITED NUCLEI

Unauthenticated Remote Code Execution - Bricks <= 1.9.6

Title source: nuclei

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.

Exploits (26)

nomisec WORKING POC 179 stars
by Chocapikk · remote
https://github.com/Chocapikk/CVE-2024-25600
nomisec WORKING POC 51 stars
by K3ysTr0K3R · remote
https://github.com/K3ysTr0K3R/CVE-2024-25600-EXPLOIT
nomisec WORKING POC 31 stars
by Christbowel · remote
https://github.com/Christbowel/CVE-2024-25600_Nuclei-Template
nomisec WORKING POC 13 stars
by so1icitx · remote
https://github.com/so1icitx/CVE-2024-25600
nomisec WORKING POC 8 stars
by Tornad0007 · remote
https://github.com/Tornad0007/CVE-2024-25600-Bricks-Builder-plugin-for-WordPress
github WRITEUP 7 stars
by cybersecplayground · poc
https://github.com/cybersecplayground/PoC-and-CVE-Reports/tree/main/2024/CVE-2024-25600.md
nomisec WORKING POC 3 stars
by hy011121 · remote
https://github.com/hy011121/CVE-2024-25600-wordpress-Exploit-RCE
nomisec WORKING POC 1 stars
by X-Projetion · remote
https://github.com/X-Projetion/WORDPRESS-CVE-2024-25600-EXPLOIT-RCE
github WORKING POC
by estebanzarate · pythonremote
https://github.com/estebanzarate/CVE-2024-25600-WordPress-Bricks-Builder-RCE-PoC
nomisec WORKING POC
by h0w1tzxr · poc
https://github.com/h0w1tzxr/TryHack3M-Bricks-Heist
nomisec WORKING POC
by ranjithxploit · remote
https://github.com/ranjithxploit/CVE-2024-25600
nomisec WRITEUP
by Anjai7 · poc
https://github.com/Anjai7/TryHack3M-Bricks-Heist
nomisec WORKING POC
by r0otk3r · remote
https://github.com/r0otk3r/CVE-2024-25600
nomisec WORKING POC
by DedsecTeam-BlackHat · remote
https://github.com/DedsecTeam-BlackHat/Poleposph
nomisec SCANNER
by ivanbg2004 · remote
https://github.com/ivanbg2004/ODH-BricksBuilder-CVE-2024-25600-THM
nomisec WORKING POC
by meli0dasH4ck3r · remote
https://github.com/meli0dasH4ck3r/cve-2024-25600
nomisec WORKING POC
by Sibul-Dan-Glokta · remote
https://github.com/Sibul-Dan-Glokta/test-task-CVE-2024-25600
nomisec WORKING POC
by w666-glitch · poc
https://github.com/w666-glitch/CVE-2024-25600
nomisec WORKING POC
by wh6amiGit · remote
https://github.com/wh6amiGit/CVE-2024-25600
nomisec WORKING POC
by KaSooMi0228 · remote
https://github.com/KaSooMi0228/CVE-2024-25600-Bricks-Builder-WordPress
nomisec WORKING POC
by WanLiChangChengWanLiChang · remote
https://github.com/WanLiChangChengWanLiChang/CVE-2024-25600
nomisec WORKING POC
by NanoWraith · poc
https://github.com/NanoWraith/CVE-2024-25600
nomisec WORKING POC
by svchostmm · remote
https://github.com/svchostmm/CVE-2024-25600-mass
vulncheck_xdb WORKING POC
remote
https://github.com/k3lpi3b4nsh33/CVE-2024-25600
metasploit WORKING POC EXCELLENT
by Calvin Alkan, Valentin Lobstein · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/wp_bricks_builder_rce.rb

Nuclei Templates (1)

Unauthenticated Remote Code Execution – Bricks <= 1.9.6
CRITICALVERIFIEDby christbowel

Scores

CVSS v3 10.0
EPSS 0.9390
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

VulnCheck KEV 2024-02-19
CWE
CWE-94
Status published
Products (1)
Codeer Limited/Bricks Builder < 1.9.6
Published Jun 04, 2024
Tracked Since Feb 18, 2026