![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMN1121-c4tWdmC8-9N9p2NpvGXHb5IGb3lDyN84Vai1Ra-aymi_QshCJMYkJigL8lJXId3dj3savWAv9gU7L34I8rMQMjXJaJrbrws9eSQlQ9D04FJw4qWH1LjH4i5SWJJtH7fRlpjFVJIN26xEc3WkCZd-A2YzDc41sDCAgJSzdZX6b7PWOujkYXiQSB/s1600/wordpress.jpg)
A critical security flaw in the Bricks theme for WordPress is being actively exploited by threat actors to run arbitrary PHP code on susceptible installations.
The flaw, tracked as CVE-2024-25600 (CVSS score: 9.8), enables unauthenticated attackers to achieve remote code execution. It impacts all versions of the Bricks up to and including 1.9.6.
It has been addressed by the theme developers in&
Source:: The Hackers News