PT-2025-31168 · WordPress · Bricks Theme For Wordpress

Jamie Burchell

·

Published

2025-07-29

·

Updated

2025-08-03

·

CVE-2025-6495

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bricks theme for WordPress versions prior to 1.12.5
Description The Bricks theme for WordPress is susceptible to a blind SQL Injection issue via the p parameter. Insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries allow unauthenticated attackers to inject additional SQL queries, potentially extracting sensitive information from the database.
Recommendations Update the Bricks theme for WordPress to version 1.12.5 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-6495

Affected Products

Bricks Theme For Wordpress