WordPress Bricks Theme Under Active Attack: Critical Flaw Impacts 25,000+ Sites
ID: 1a6ebc70-f38e-5fbb-9f36-8ac42b87de93
STIX ID: report--1a6ebc70-f38e-5fbb-9f36-8ac42b87de93
Feed Name: The Hacker News
Threat Score
A critical unauthenticated remote code execution vulnerability (CVE-2024-25600, CVSS 9.8) in the Bricks WordPress theme (all versions up to and including 1.9.6) is being actively exploited; the developer released patch 1.9.6.1 on Feb 13, 2024 and users are urged to update immediately. Wordfence reported dozens of exploit attempts beginning Feb 14 and the report lists multiple attacker IP addresses and technical details about nonce misuse and insecure permission checks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
