Hackers exploit critical RCE flaw in Bricks WordPress site builder
ID: 44ddf069-972d-5703-ae48-4e7d8ba6996f
STIX ID: report--44ddf069-972d-5703-ae48-4e7d8ba6996f
Feed Name: Bleeping Computer
A critical unauthenticated RCE (CVE-2024-25600) in the Bricks Builder WordPress theme was disclosed in February 2024; a patch (1.9.6.1) was released on Feb 13 but active exploitation was observed starting Feb 14. Attackers abuse an eval call in prepare_query_vars_from_settings via REST endpoints to run arbitrary PHP, and post-exploitation activity has included malware that can disable Wordfence and Sucuri; multiple attacker IPs and detections by security vendors are reported. Administrators are urged to update Bricks installations to 1.9.6.1 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
