VendorsBricks Builderbricksall versions
Vulnerabilities

Bricks Builder Bricks 1.0 for WordPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2022-3401
The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include executable code blocks in website content in versions 1.2 to 1.5.3. This, combined with the missing authorization vulnerability (CVE-2022-3400), makes it possible for authenticated attackers with minimal permissions, such as a subscriber, can edit any page, post, or template on the vulnerable WordPress website and inject a code execution block that can be used to achieve remote code execution.
Published 2022-10-28 · Modified
8.8EPSS 0.017
CVE-2024-2297
Bricksbuilder <= 1.9.6.1 - Authenticated (Contributor+) Privilege Escalation via create_autosave
Published 2025-02-27 · Analyzed
8.8EPSS 0.004
CVE-2022-3400
The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in versions 1.0 to 1.5.3. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to edit any page, post, or template on the vulnerable WordPress website.
Published 2022-10-28 · Modified
6.5EPSS 0.006
CVE-2023-3410
Bricks <= 1.10.1 - Authenticated (Bricks Page Builder Access+) Stored Cross-Site Scripting
Published 2024-09-14 · Analyzed
5.4EPSS 0.003
CVE-2023-3409
Bricks <= 1.8.1 - Cross-Site Request Forgery via reset_settings
Published 2024-08-17 · Analyzed
5.4EPSS 0.002
CVE-2024-4874
Bricks Builder <= 1.9.8 - Insecure Direct Object Reference
Published 2024-06-22 · Modified
4.3EPSS 0.003
CVE-2023-3408
Bricks <= 1.8.1 - Cross-Site Request Forgery via save_settings
Published 2024-08-17 · Analyzed
4.3EPSS 0.002