CVE-2024-2297

The Bricks theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.6.1. This is due to insufficient validation checks placed on the create_autosave AJAX function. This makes it possible for authenticated attackers, with contributor-level access and above, to execute arbitrary PHP code with elevated (administrator-level) privileges. NOTE: Successful exploitation requires (1) the Bricks Builder to be enabled for posts (2) Builder access to be enabled for contributor-level users, and (3) "Code Execution" to be enabled for administrator-level users within the theme's settings.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bricksbuilder:bricks:*:*:*:*:*:wordpress:*:*

History

11 Mar 2025, 19:39

Type Values Removed Values Added
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/cb075e85-75fc-4008-8270-4d1064ace29e?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/cb075e85-75fc-4008-8270-4d1064ace29e?source=cve - Third Party Advisory
References () https://bricksbuilder.io/release/bricks-1-9-7/ - () https://bricksbuilder.io/release/bricks-1-9-7/ - Release Notes
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 8.8
First Time Bricksbuilder
Bricksbuilder bricks
CPE cpe:2.3:a:bricksbuilder:bricks:*:*:*:*:*:wordpress:*:*

27 Feb 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-27 06:15

Updated : 2025-03-11 19:39


NVD link : CVE-2024-2297

Mitre link : CVE-2024-2297


JSON object : View

Products Affected

bricksbuilder

  • bricks
CWE
CWE-269

Improper Privilege Management

NVD-CWE-noinfo