Junglewise Threat Intelligence

CVE-2026-39596: Creative Themes Blocksy Companion Pro SQL injection

CVE-2026-39596 · Severity: critical · CVSS 9.3 · Published 2026-06-17

Technologies: Creative Themes Blocksy Companion Pro. Vendors: Creative Themes.

Executive brief

Blocksy Companion Pro, a premium WordPress plugin used to extend the functionality of the Blocksy theme, contains a critical security flaw. An unauthenticated attacker can remotely access and manipulate the website's database. This could lead to the theft of sensitive customer information, administrative account takeover, or disruption of site operations.

Technical details

A SQL injection vulnerability exists in the Blocksy Companion Pro plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows an unauthenticated remote attacker to send specially crafted requests to the application to interact directly with the underlying database. Successful exploitation can lead to unauthorized data exfiltration, modification of database records, or partial denial of service. The vulnerability is addressed in version 2.1.29.

Affected products

  • Creative Themes Blocksy Companion Pro < 2.1.29

Timeline

  • 2026-02-03: other: Vulnerability reported by Nguyen Ba Khanh
  • 2026-04-08: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date

References

Related threats