PT-2025-31168 · WordPress · Bricks Theme For Wordpress

Jamie Burchell

·

Published

2025-07-29

·

Updated

2025-07-29

·

CVE-2025-6495

CVSS v3.1
7.5
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

Bricks theme for WordPress versions prior to 1.12.5

Description:

The Bricks theme for WordPress is susceptible to a blind SQL Injection issue via the `p` parameter. Insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries allow unauthenticated attackers to inject additional SQL queries, potentially extracting sensitive information from the database.

Recommendations:

Update the Bricks theme for WordPress to version 1.12.5 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-6495

Affected Products

Bricks Theme For Wordpress