Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-58480: Blocksy Companion Pro < 2.1.47 allows attackers to upload malicious files
CVE-2026-58480
CVE-2026-58480
Summary
The Blocksy Companion Pro plugin for WordPress is affected if it's version is less than 2.1.47. Attackers can upload malicious files, such as executable code, which can lead to unauthorized access and control of the website. To fix this, update the plugin to version 2.1.47 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| creative themes | blocksy companion | <= 2.1.46 |
Original title
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension vali...
Original description
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.
mitre CVSS3.1
9.8
Vulnerability type
CWE-434
Unrestricted File Upload
- https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blocksy... third-party-advisory
- https://patchstack.com/database/wordpress/plugin/blocksy-companion/vulnerability... third-party-advisory
- https://wordpress.org/plugins/blocksy-companion/ product patch
- https://www.vulncheck.com/advisories/blocksy-companion-pro-unauthenticated-file-... third-party-advisory
Published: 8 Jul 2026 · Updated: 23 Jul 2026 · First seen: 8 Jul 2026