BricksBuilder records
8 published records for vendor bricksbuilder.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 12.5%
- Pre-auth RCE
- 1
- With a fix record
- 12.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-269 Improper Privilege Management1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
66This week | CVE-2024-25600Weaponized | WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerabilitycodeer limited · bricks builder · CWE-94 | Critical10.0 | — | 88.2% | Jun 4, 2024 |
36Monitor | CVE-2022-3401No exploit | The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include executable code blocbricksbuilder · bricks · CWE-94 | High8.8 | — | 1.7% | Oct 28, 2022 |
35Monitor | CVE-2024-2297No exploit | Bricksbuilder <= 1.9.6.1 - Authenticated (Contributor+) Privilege Escalation via create_autosavebricksbuilder · bricks · CWE-269 | High8.8 | — | 0.4% | Feb 27, 2025 |
26Monitor | CVE-2022-3400No exploit | The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action ibricksbuilder · bricks · CWE-862 | Medium6.5 | — | 0.6% | Oct 28, 2022 |
21Monitor | CVE-2023-3410No exploit | Bricks <= 1.10.1 - Authenticated (Bricks Page Builder Access+) Stored Cross-Site Scriptingbricksbuilder · bricks · CWE-79 | Medium5.4 | — | 0.3% | Sep 14, 2024 |
17Monitor | CVE-2024-4874No exploit | Bricks Builder <= 1.9.8 - Insecure Direct Object Referencebricksbuilder · bricks · CWE-639 | Medium4.3 | — | 0.3% | Jun 22, 2024 |
17Monitor | CVE-2023-3408No exploit | Bricks <= 1.8.1 - Cross-Site Request Forgery via save_settingsbricksbuilder · bricks · CWE-352 | Medium4.3 | — | 0.2% | Aug 17, 2024 |
17Monitor | CVE-2023-3409No exploit | Bricks <= 1.8.1 - Cross-Site Request Forgery via reset_settingsbricksbuilder · bricks · CWE-352 | Medium4.3 | — | 0.2% | Aug 17, 2024 |
- CVE-2024-2560066This week
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
CriticalCVSS 10.0WeaponizedEPSS 88%codeer limited · bricks builderJun 4, 2024
- CVE-2022-340136Monitor
The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include executable code bloc
HighCVSS 8.8No exploitEPSS 2%bricksbuilder · bricksOct 28, 2022
- CVE-2024-229735Monitor
Bricksbuilder <= 1.9.6.1 - Authenticated (Contributor+) Privilege Escalation via create_autosave
HighCVSS 8.8No exploitEPSS 0%bricksbuilder · bricksFeb 27, 2025
- CVE-2022-340026Monitor
The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action i
MediumCVSS 6.5No exploitEPSS 1%bricksbuilder · bricksOct 28, 2022
- CVE-2023-341021Monitor
Bricks <= 1.10.1 - Authenticated (Bricks Page Builder Access+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%bricksbuilder · bricksSep 14, 2024
- CVE-2024-487417Monitor
Bricks Builder <= 1.9.8 - Insecure Direct Object Reference
MediumCVSS 4.3No exploitEPSS 0%bricksbuilder · bricksJun 22, 2024
- CVE-2023-340817Monitor
Bricks <= 1.8.1 - Cross-Site Request Forgery via save_settings
MediumCVSS 4.3No exploitEPSS 0%bricksbuilder · bricksAug 17, 2024
- CVE-2023-340917Monitor
Bricks <= 1.8.1 - Cross-Site Request Forgery via reset_settings
MediumCVSS 4.3No exploitEPSS 0%bricksbuilder · bricksAug 17, 2024