Junglewise Threat Intelligence

CVE-2026-57315: Creative Themes Blocksy Companion Pro remote code execution

CVE-2026-57315 · Severity: high · CVSS 8.5 · Published 2026-06-26

Technologies: Creative Themes Blocksy Companion Pro. Vendors: Creative Themes.

Executive brief

Blocksy Companion Pro is a premium WordPress plugin used to extend the functionality of the Blocksy theme. A security vulnerability allows users with 'Contributor' level access to execute malicious code on the server. This could lead to a complete takeover of the website, unauthorized data access, or the installation of backdoors.

Technical details

A remote code execution (RCE) vulnerability exists in the Blocksy Companion Pro plugin for WordPress due to improper control of code generation (CWE-94). The flaw allows an authenticated attacker with at least 'Contributor' privileges to inject and execute arbitrary PHP code on the server. While the attack complexity is rated as high, a successful exploit grants the attacker full control over the site's environment. The issue is fixed in version 2.1.46.

Affected products

  • Creative Themes Blocksy Companion Pro <= 2.1.45

Timeline

  • 2026-04-28: disclosed: Reported by researcher daroo
  • 2026-06-26: advisory: NVD and Patchstack published the advisory
  • 2026-06-26: patched: Version 2.1.46 released to address the vulnerability

References

Related threats