← Back to CVE List

CVE-2022-3400

Published: 2022-10-28T17:15Z
Last Modified: 2024-11-21T07:19Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in versions 1.0 to 1.5.3. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to edit any page, post, or template on the vulnerable WordPress website. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt