Executive brief
Blocksy Companion Pro is a premium WordPress plugin used to extend the functionality of the Blocksy theme. A security vulnerability allows users with 'Contributor' level access to execute arbitrary code on the website's server. This could lead to a complete takeover of the site, data theft, or the installation of persistent backdoors.
Technical details
A Remote Code Execution (RCE) vulnerability exists in the Blocksy Companion Pro plugin for WordPress due to improper control of code generation (CWE-94). The flaw allows an authenticated attacker with at least 'Contributor' privileges to inject and execute arbitrary PHP code on the server. The vulnerability is assigned a CVSS score of 9.9 because it allows for a total impact on confidentiality, integrity, and availability, and can lead to a full site compromise. The issue is resolved in version 2.1.38.
Affected products
- Creative Themes Blocksy Companion Pro <= 2.1.37
Timeline
- 2026-03-13: other: Reported by Nguyen Ba Khanh
- 2026-04-22: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date
- 2026-06-17: patched: Patch confirmed available in version 2.1.38