Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total8
Critical0
High3
Medium5
Reset
Showing 1-8 of 8 records
Threat Entry Updated 2025-07-29

CVE-2025-6495 - Bricks Theme

The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and including, 1.12.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

THEME Bricks

CVE-2025-6495

HIGH CVSS 7.5 2025-07-29
Threat Entry Updated 2025-03-11

CVE-2024-2297 - Bricks Plugin

The Bricks theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.6.1. This is due to insufficient validation checks placed on the create_autosave AJAX function. This makes it possible for authenticated attackers, with contributor-level access and above, to execute arbitrary PHP code with elevated (administrator-level) privileges. NOTE: Successful exploitation requires (1) the Bricks Builder to be enabled for posts (2) Builder access to be enabled for contributor-level users, and (3) "Code Execution" to be enabled for administrator-level users within the theme's settings.

PLUGIN Bricks

CVE-2024-2297

HIGH CVSS 7.1 2025-02-27
Threat Entry Updated 2024-09-27

CVE-2023-3410 - Bricks Theme

The Bricks theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘customTag' attribute in versions up to, and including, 1.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the Bricks Builder (admin-only by default), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This becomes more of an issue when Bricks Builder access is granted to lower-privileged users.

THEME Bricks

CVE-2023-3410

MEDIUM CVSS 5.4 2024-09-14
Threat Entry Updated 2024-09-13

CVE-2023-3409 - Bricks Theme

The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'reset_settings' function. This makes it possible for unauthenticated attackers to reset the theme's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Bricks

CVE-2023-3409

MEDIUM CVSS 5.4 2024-08-17
Threat Entry Updated 2024-09-13

CVE-2023-3408 - Bricks Theme

The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'save_settings' function. This makes it possible for unauthenticated attackers to modify the theme's settings, including enabling a setting which allows lower-privileged users such as contributors to perform code execution, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Bricks

CVE-2023-3408

MEDIUM CVSS 4.3 2024-08-17
Threat Entry Updated 2024-11-21

CVE-2024-4874 - Bricks Plugin

The Bricks Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.8 via the postId parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify posts and pages created by other users including admins. As a requirement for this, an admin would have to enable access to the editor specifically for such a user or enable it for all users with a certain user account type.

PLUGIN Bricks

CVE-2024-4874

MEDIUM CVSS 4.3 2024-06-22
Threat Entry Updated 2024-11-21

CVE-2022-3401 - Bricks Theme

The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include executable code blocks in website content in versions 1.2 to 1.5.3. This, combined with the missing authorization vulnerability (CVE-2022-3400), makes it possible for authenticated attackers with minimal permissions, such as a subscriber, can edit any page, post, or template on the vulnerable WordPress website and inject a code execution block that can be used to achieve remote code execution.

THEME Bricks

CVE-2022-3401

HIGH CVSS 8.8 2022-10-28
Threat Entry Updated 2024-11-21

CVE-2022-3400 - Bricks Theme

The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in versions 1.0 to 1.5.3. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to edit any page, post, or template on the vulnerable WordPress website.

THEME Bricks

CVE-2022-3400

MEDIUM CVSS 6.5 2022-10-28
Scroll to top