Feed/CVE-2024-25600
CVE-2024-25600CRITICALCVSS 10.0

CVE-2024-25600

Published Jun 4, 2024·Updated Jun 17, 2026

NVD Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.

Public Exploits & PoCs21 found

[POC] GHSA-8qqm-fp2q-v734 — WP-Bricks-Exploit-CVE-2024-25600

CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse shells, file upload/download, async scanning, stealth mode, proxy support, and multi-threaded vulnerability scanning. For authorized security testing only.

1

PoC: 0BL1V10N-CVE-2024-25600-Bricks-Builder-plugin-for-WordPress

0BL1V10N's CVE-2024-25600 for Bricks Builder (TryHackMe) plugin for WordPress exploit

1

PoC: WORDPRESS-CVE-2024-25600-EXPLOIT-RCE

WORDPRESS-CVE-2024-25600-EXPLOIT-RCE - WordPress Bricks Builder Remote Code Execution (RCE)

1

PoC: CVE-2024-25600

Unauthenticated Remote Code Execution – Bricks <= 1.9.6

1

PoC: CVE-2024-25600-WordPress-Bricks-Builder-RCE-PoC

Unauthenticated remote code execution vulnerability in WordPress Bricks Builder <= 1.9.6. The template render endpoint accepts PHP code without authentication, allowing arbitrary command execution as the web server user.

PoC: TryHack3M-Bricks-Heist

🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up

PoC: CVE-2024-25600

Modified the CVE-2024-25600

PoC: TryHack3M-Bricks-Heist

TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identification

PoC: bricks-rce-writeup

cve-2024-25600-report

PoC: Poleposph

Tools for scan CVE-2024-25600 - WordPress Bricks Builder Remote Code Execution (RCE)

PoC: ODH-BricksBuilder-CVE-2024-25600-THM

OD&H's scanner for CVE-2024-25600 vulnerability in the Bricks Builder WordPress plugin. For use in Try Hack Me (THM) environments.

PoC: cve-2024-25600

PoC for CVE-2024-25600

PoC: CVE-2024-25600

Unauthenticated RCE exploit for CVE-2024-25600 in WordPress Bricks Builder <= 1.9.6. Executes arbitrary code remotely.

PoC: CVE-2024-25600

CVE-2024-25600 exploit (python 3)

PoC: test-task-CVE-2024-25600

Repository for internship test task.

PoC: CVE-2024-25600

Unauthenticated Remote Code Execution – Bricks

PoC: 0BL1V10N-CVE-2024-25600-Bricks-Builder-plugin-for-WordPress

This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress. The vulnerability allows for unauthenticated remote code execution on affected websites. The tool automates the exploitation process by retrieving nonces and sending specially crafted requests to execute arbitrary commands.

PoC: CVE-2024-25600-EXPLOIT

A PoC exploit for CVE-2024-25600 - WordPress Bricks Builder Remote Code Execution (RCE)

PoC: CVE-2024-25600-wordpress-Exploit-RCE

(Mirorring)

PoC: CVE-2024-25600-Bricks-Builder-plugin-for-WordPress

This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress. The vulnerability allows for unauthenticated remote code execution on affected websites. The tool automates the exploitation process by retrieving nonces and sending specially crafted requests to execute arbitrary commands.

PoC: CVE-2024-25600_Nuclei-Template

Nuclei template and information about the POC for CVE-2024-25600

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free