CVE-2022-3401
Bricks 1.2 - 1.5.3 - Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include executable code blocks in website content in versions 1.2 to 1.5.3. This, combined with the missing authorization vulnerability (CVE-2022-3400), makes it possible for authenticated attackers with minimal permissions, such as a subscriber, can edit any page, post, or template on the vulnerable WordPress website and inject a code execution block that can be used to achieve remote code execution.
El tema Bricks para WordPress es vulnerable a la ejecución remota de código debido a que permite a los editores de sitios incluir bloques de código ejecutables en el contenido del sitio web en las versiones 1.2 a 1.5.3. Esto, combinado con la vulnerabilidad de autorización faltante (CVE-2022-3400), hace posible que atacantes autenticados con permisos mínimos, como un suscriptor, puedan editar cualquier página, publicación o plantilla en el sitio web vulnerable de WordPress e inyectar un código de ejecución. bloque que se puede utilizar para lograr la ejecución remota de código.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-03 CVE Reserved
- 2022-10-03 CVE Published
- 2024-08-03 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.wordfence.com/vulnerability-advisories-continued/#CVE-2022-3401 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bricksbuilder.io | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bricksbuilder Search vendor "Bricksbuilder" | Bricks Search vendor "Bricksbuilder" for product "Bricks" | >= 1.2 < 1.5.4 Search vendor "Bricksbuilder" for product "Bricks" and version " >= 1.2 < 1.5.4" | wordpress |
Affected
|