HomeSecurityHackers exploit vulnerability in Bricks Builder WordPress Theme

Hackers exploit vulnerability in Bricks Builder WordPress Theme

Hackers are exploiting a critical remote code execution vulnerability affecting the WordPress theme, Bricks Builder Theme. The goal is to execute malicious PHP code on vulnerable sites.

Bricks Builder vulnerability

The Bricks Builder Theme is a premium WordPress theme and has approximately 25,000 active installations.

On February 10, a researcher named “snicco” discovered a vulnerability tracked as CVE-2024-25600. It affects the Bricks Builder Theme that is installed with its default configuration.

The vulnerability is related to an eval function call in the “prepare_query_vars_from_settings” function. Successful exploitation of this vulnerability allows an unauthenticated user to execute PHP code.

See also: Better Search Replace: Hackers target vulnerability in WordPress plugin

Patchstack, a platform that deals with WordPress security issues, received the vulnerability report and notified the Bricks team. On February 13, a update (1.9.6.1) was released that addresses the issue.

The vendor urged users to upgrade to the latest version as soon as possible.

“The likelihood of exploitation increases the longer the implementation of update 1.9.6.1,” Bricks’ bulletin states.

“Update all Bricks sites to the latest Bricks version 1.9.6.1 as soon as possible. The sooner, the better“.

On the same day, snicco revealed some details about the vulnerability. In a more recent post, he also presented a demo of the attack but not the exploit code.

Hackers exploit the vulnerability in the Bricks Builder Theme

According to Patchstack, exploitation attempts of the vulnerability were detected, which started on February 14.

The company explains that the flaw results from executing user-controlled input via the eval function in prepare_query_vars_from_settings, with $php_query_raw being constructed by queryEditor.

Exploitation is possible via REST API endpoints for server-side rendering, since access is possible without authentication.

See also: Balada Injector Malware has infected 6,700 WordPress sites

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Patchstack observed that after exploiting the vulnerability in the Bricks Builder Theme, the attackers used specific malware that can disable security plugins such as Wordfence and Sucuri.

The following IP addresses have been associated with most of the attacks:

  • 200.251.23.57
  • 92.118.170.216
  • 103.187.5.128
  • 149.202.55.79
  • 5.252.118.211
  • 91.108.240.52

It is recommended that Bricks users upgrade to version 1.9.3.1 immediately!

Bricks Builder WordPress Theme

Importance of WordPress protection

Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.

Additionally, an unsecured WordPress site can undermine the trust and credibility you have built with customers . If their data is compromised, they are likely to take legal action against you and switch to other companies.

See also: POST SMTP Mailer: Vulnerabilities in WordPress plugin – Update immediately!

Securing your website is also important for maintaining the consistency and credibility of your content. If a hacker breaks into your website and corrupts the content, it can give the impression that you are not doing enough with your website.

In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers’ trust, preserving your company’s reputation, and staying on top of the competition.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS