Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-58480: Blocksy Companion Pro < 2.1.47 allows attackers to upload malicious files

CVE-2026-58480 CVE-2026-58480
Summary

The Blocksy Companion Pro plugin for WordPress is affected if it's version is less than 2.1.47. Attackers can upload malicious files, such as executable code, which can lead to unauthorized access and control of the website. To fix this, update the plugin to version 2.1.47 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
creative themes blocksy companion <= 2.1.46
Original title
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension vali...
Original description
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.
mitre CVSS3.1 9.8
Vulnerability type
CWE-434 Unrestricted File Upload
Published: 8 Jul 2026 · Updated: 23 Jul 2026 · First seen: 8 Jul 2026