Vulnerabilities

Websites Hacked via Vulnerability in Bricks Builder WordPress Plugin

Attackers are exploiting a recent remote code execution flaw in the Bricks Builder WordPress plugin to deploy malware.

Attackers are exploiting a recent remote code execution flaw in the Bricks Builder WordPress plugin to deploy malware.

Attackers are exploiting a recently patched vulnerability in the Bricks Builder plugin for WordPress to hack websites and deploy malware, WordPress security company Patchstack reports.

The issue, tracked as CVE-2024-25600, is described as a remote code execution (RCE) flaw that can be exploited without authentication to execute arbitrary PHP code on an affected WordPress website.

The bug was identified in the ‘prepare_query_vars_from_settings’ function, which is called from different processes in the code, including the Bricks\Query class, which manages the rendering of WordPress post queries, and which uses PHP’s eval function, security researcher Calvin Alkan explains.

An analysis of the process calls revealed that no proper permissions or role checks were applied when a function handling a REST API endpoint was involved.

Because the function only checks for a nonce value and Bricks outputs a valid nonce in the frontend of a WordPress site, even for unauthenticated users, an attacker can easily retrieve the nonce and trigger the RCE. On Monday, the security researcher published proof-of-concept (PoC) code for this bug.

“Note that this vulnerability can be reproduced with an unauthenticated user with the default installation configuration of the theme,” Patchstack points out.

Advertisement. Scroll to continue reading.

According to the security firm, threat actors are already exploiting the vulnerability and, in some cases, they deploy malware specifically designed to disable security plugins.

Bricks announced patches for the vulnerability on February 13, when Bricks Builder version 1.9.6.1 was released, urging users to update as soon as possible.

“As of the time of this release, there’s no evidence that this vulnerability has been exploited. However, the potential for exploitation increases the longer the update to 1.9.6.1 is delayed. We advise you to update all your Bricks sites immediately,” Bricks said.

The first exploitation attempts were observed on February 14 and Patchstack says that the attacks are originating from multiple IP addresses.

Bricks Builder is a visual site builder for WordPress that does not require technical expertise to use. Its premium version has roughly 25,000 active installations.

Related: Flaws in Backup Migration and Elementor WordPress Plugins Allow Remote Code Execution

Related: WordPress 6.4.2 Patches Remote Code Execution Vulnerability

Related: WordPress Websites Hacked via Royal Elementor Plugin Zero-Day

Related Content

Ransomware

The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.

Vulnerabilities

The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations.

Vulnerabilities

CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access.

Vulnerabilities

The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution.

Malware & Threats

The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.

Vulnerabilities

Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure.

Vulnerabilities

The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server.

Risk Management

Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version