CVE-2024-2297

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 27, 2025
Updated: Mar 11, 2025
CWE ID 269

Summary

CVE-2024-2297 is a privilege escalation vulnerability affecting the Bricks theme for WordPress. In versions up to 1.9.6.1, the create_autosave AJAX function lacks sufficient validation checks, allowing authenticated attackers with contributor-level access and above to execute arbitrary PHP code with elevated (administrator-level) privileges. Successfully exploiting this vulnerability relies on the Bricks Builder being enabled for posts, Builder access being enabled for contributor-level users, and "Code Execution" being enabled for administrator-level users within the theme's settings.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share