Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-57624: Blocksy Companion Pro plugin <= 2.1.46 allows attackers to run malicious code.
CVE-2026-57624 · published 2 months ago
Summary
The Blocksy Companion Pro plugin for WordPress has a security issue that allows hackers to run their own code on your website without needing a password. This means they could potentially delete or modify your website's content. To fix this, update the plugin to the latest version or remove it if you don't need it.
What to do
- Update creative themes blocksy companion pro to version 2.1.47.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| creative themes | blocksy companion pro |
<= 2.1.46 Fix: upgrade to 2.1.47
|
Original advisory text
WordPress Blocksy Companion Pro plugin <= 2.1.46 - Remote Code Execution (RCE) vulnerability
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
Severity
10.0
Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published2 Jul 2026
Updated27 Sep 2026
First seen2 Jul 2026
Track software like this
Free during beta