CVE-2022-3401
Last modified
CVE-2022-3401 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include executable code blocks in website content in versions 1.2 to 1.5.3. This, combined with the missing authorization vulnerability (CVE-2022-3400), makes it possible for authenticated attackers with minimal permissions, such as a subscriber, can edit any page, post, or template on the vulnerable WordPress website and inject a code execution block that can be used to achieve remote code execution.. EPSS estimates a 1.56% chance of exploitation in the next 30 days.
Description
The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include executable code blocks in website content in versions 1.2 to 1.5.3. This, combined with the missing authorization vulnerability (CVE-2022-3400), makes it possible for authenticated attackers with minimal permissions, such as a subscriber, can edit any page, post, or template on the vulnerable WordPress website and inject a code execution block that can be used to achieve remote code execution.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bricksbuilder | Bricks | >= 1.2, < 1.5.4 |
References
- https://bricksbuilder.io/Product, Vendor Advisory
- https://www.wordfence.com/vulnerability-advisories-continued/#CVE-2022-3401Third Party Advisory
- https://bricksbuilder.io/Product, Vendor Advisory
- https://www.wordfence.com/vulnerability-advisories-continued/#CVE-2022-3401Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3401?
How severe is CVE-2022-3401?
How do I fix CVE-2022-3401?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-34002The ‘document’ parameter of PDS Vista 7’s /application/docum…6.5
- CVE-2022-34005An issue was discovered in TitanFTP (aka Titan FTP) NextGen …9.8
- CVE-2022-34006An issue was discovered in TitanFTP (aka Titan FTP) NextGen …7.8
- CVE-2022-34007EQS Integrity Line Professional through 2022-07-01 allows a …6.1
- CVE-2022-34008Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allo…7.8
- CVE-2022-34009Fossil 2.18 on Windows allows attackers to cause a denial of…5.5
- CVE-2022-34011OneBlog v2.3.4 was discovered to contain a Server-Side Reque…4.3
- CVE-2022-34012Insecure permissions in OneBlog v2.3.4 allows low-level admi…6.5
- CVE-2022-34013OneBlog v2.3.4 was discovered to contain a Server-Side Reque…4.3
- CVE-2022-3402The Log HTTP Requests plugin for WordPress is vulnerable to …6.1
- CVE-2022-34020Cross Site Request Forgery (CSRF) vulnerability in ResIOT Re…8.8
- CVE-2022-34021Multiple Cross Site Scripting (XSS) vulnerabilities in ResIO…5.4
Are you affected by CVE-2022-3401?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
