Junglewise Threat Intelligence

CVE-2026-40783: Creative Themes Blocksy Companion Pro remote code execution

CVE-2026-40783 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Creative Themes Blocksy Companion Pro. Vendors: Creative Themes.

Executive brief

Blocksy Companion Pro is a premium WordPress plugin used to extend the functionality of the Blocksy theme. A security vulnerability allows users with 'Contributor' level access to execute arbitrary code on the website's server. This could lead to a complete takeover of the site, data theft, or the installation of persistent backdoors.

Technical details

A Remote Code Execution (RCE) vulnerability exists in the Blocksy Companion Pro plugin for WordPress due to improper control of code generation (CWE-94). The flaw allows an authenticated attacker with at least 'Contributor' privileges to inject and execute arbitrary PHP code on the server. The vulnerability is assigned a CVSS score of 9.9 because it allows for a total impact on confidentiality, integrity, and availability, and can lead to a full site compromise. The issue is resolved in version 2.1.38.

Affected products

  • Creative Themes Blocksy Companion Pro <= 2.1.37

Timeline

  • 2026-03-13: other: Reported by Nguyen Ba Khanh
  • 2026-04-22: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date
  • 2026-06-17: patched: Patch confirmed available in version 2.1.38

References

Related threats