Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-58480: Blocksy Companion Pro < 2.1.47 allows attackers to upload malicious files
CVE-2026-58480 · published 2 months ago
Summary
The Blocksy Companion Pro plugin for WordPress is affected if it's version is less than 2.1.47. Attackers can upload malicious files, such as executable code, which can lead to unauthorized access and control of the website. To fix this, update the plugin to version 2.1.47 or later.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| creative themes | blocksy companion | <= 2.1.46 |
Original advisory text
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension vali...
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.
References
- https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blocksy... third-party-advisory
- https://patchstack.com/database/wordpress/plugin/blocksy-companion/vulnerability... third-party-advisory
- https://wordpress.org/plugins/blocksy-companion/ product patch
- https://www.vulncheck.com/advisories/blocksy-companion-pro-unauthenticated-file-... third-party-advisory
Severity
9.2
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 4%
Type
CWE-434Unrestricted File Upload
Timeline
Published8 Jul 2026
Updated25 Sep 2026
First seen8 Jul 2026
Track software like this
Free during beta