Junglewise Threat Intelligence

CVE-2026-12430: CreativeThemesHQ Blocksy Companion Stored XSS in admin settings

CVE-2026-12430 · Severity: medium · CVSS 4.4 · Published 2026-06-19

Executive brief

The Blocksy Companion plugin for WordPress, which provides extended features for the Blocksy theme, contains a security flaw in its administrative settings. This vulnerability allows users with editor-level access or higher to plant malicious scripts on the website. These scripts can then execute in the browsers of other visitors or administrators, potentially leading to unauthorized actions or data theft, particularly on multi-site WordPress installations.

Technical details

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within the admin settings, specifically affecting the product reviews extension. An authenticated attacker with editor-level permissions or higher can inject arbitrary web scripts into the database. These scripts execute when a user accesses the affected page. This vulnerability primarily impacts WordPress multi-site installations or environments where the 'unfiltered_html' capability has been disabled for high-level users. The issue is present in all versions up to and including 2.1.45.

Affected products

  • CreativeThemesHQ Blocksy Companion up to and including 2.1.45

Timeline

  • 2026-06-19: disclosed: CVE published by Wordfence/NVD

References