Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-57624: Blocksy Companion Pro plugin <= 2.1.46 allows attackers to run malicious code.
CVE-2026-57624
CVE-2026-57624
Summary
The Blocksy Companion Pro plugin for WordPress has a security issue that allows hackers to run their own code on your website without needing a password. This means they could potentially delete or modify your website's content. To fix this, update the plugin to the latest version or remove it if you don't need it.
What to do
- Update creative themes blocksy companion pro to version 2.1.47.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| creative themes | blocksy companion pro |
<= 2.1.46 Fix: upgrade to 2.1.47
|
Original title
WordPress Blocksy Companion Pro plugin <= 2.1.46 - Remote Code Execution (RCE) vulnerability
Original description
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
nvd CVSS3.1
10.0
Vulnerability type
CWE-94
Code Injection
Published: 2 Jul 2026 · Updated: 23 Jul 2026 · First seen: 2 Jul 2026