Executive brief
Blocksy Companion Pro is a premium WordPress plugin used to extend the functionality of the Blocksy theme. A security vulnerability allows users with 'Contributor' level access to execute malicious code on the server. This could lead to a complete takeover of the website, unauthorized data access, or the installation of backdoors.
Technical details
A remote code execution (RCE) vulnerability exists in the Blocksy Companion Pro plugin for WordPress due to improper control of code generation (CWE-94). The flaw allows an authenticated attacker with at least 'Contributor' privileges to inject and execute arbitrary PHP code on the server. While the attack complexity is rated as high, a successful exploit grants the attacker full control over the site's environment. The issue is fixed in version 2.1.46.
Affected products
- Creative Themes Blocksy Companion Pro <= 2.1.45
Timeline
- 2026-04-28: disclosed: Reported by researcher daroo
- 2026-06-26: advisory: NVD and Patchstack published the advisory
- 2026-06-26: patched: Version 2.1.46 released to address the vulnerability