CVE-2024-2297
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-2297 is a privilege escalation vulnerability affecting the Bricks theme for WordPress. In versions up to 1.9.6.1, the create_autosave AJAX function lacks sufficient validation checks, allowing authenticated attackers with contributor-level access and above to execute arbitrary PHP code with elevated (administrator-level) privileges. Successfully exploiting this vulnerability relies on the Bricks Builder being enabled for posts, Builder access being enabled for contributor-level users, and "Code Execution" being enabled for administrator-level users within the theme's settings.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.