Bricks Theme Vulnerable to Cross-Site Request Forgery
CVE-2023-3409

4.3MEDIUM

Key Information:

Vendor
Bricks Builder
Status
Bricks
Vendor
CVE Published:
17 August 2024

Summary

The Bricks theme for WordPress exhibits a vulnerability that allows for Cross-Site Request Forgery (CSRF), specifically in versions up to and including 1.8.1. This security flaw arises from inadequate nonce validation in the 'reset_settings' function. As a result, unauthenticated attackers could potentially manipulate the theme's settings by crafting a forged request. These attackers often rely on social engineering tactics to mislead site administrators into clicking on malicious links, thereby executing the forged requests. It is critical for users of the Bricks theme to apply necessary updates to ensure their website remains secure.

Affected Version(s)

Bricks * <= 1.8.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ramuel Gall
.