Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-25600 PoC — WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability

Source
Associated Vulnerability
Title: WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability (CVE-2024-25600)
Description:Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.
Description
Repository for internship test task. 
Readme
# test-task-CVE-2024-25600
Repository for internship test-task. 

### Step 0: Clone this git repo
```
git clone https://github.com/Sibul-Dan-Glokta/test-task-CVE-2024-25600
```

### Step 1: Create docker containers

#### Start Docker daemon

```
sudo systemctl start docker.service
```

#### Start Docker Containers
To start the docker container navigate to the wp_container directory
```
cd path/to/wp_container
```
Start the docker containers
```
sudo docker compose up -d
```

#### (optional) Check if the wordpress page started
The WP site may take roughly 30 seconds to get working properly. To validate if the WP page started issue the following command:
```
curl http://127.0.0.1:8080
```
The output should display HTML code. and no errors


### Step 2: Exploit the website
#### (If necessary) create a python virtual environment
```
python -m venv /path/to/new/virtual/environment
```

#### Install the necessary dependencies
To install the necessary dependencies navigate to the exploit directory and run the following command:
```
path/to/new/virtual/environment/bin/pip install -r requirements.txt
```

#### Run the exploit
While in the exploit directory to run the exploit issue the following command:
```
path/to/new/virtual/environment/bin/python3 exploit.py -u http://127.0.0.1:8080

```
This will crant you access to the server shell as www-data. And you will have access to /etc/passwd.
Output from exploit script and whoami
![alt text](image.png)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →