Executive brief
Blocksy Companion Pro is a premium WordPress plugin used to extend the functionality of the Blocksy theme. A critical security flaw allows an unauthenticated attacker to remotely execute code on the website's server. This could lead to a total takeover of the website, theft of customer data, or the installation of malware, potentially impacting the business's reputation and operational continuity.
Technical details
The Blocksy Companion Pro plugin for WordPress is vulnerable to unauthenticated Remote Code Execution (RCE) due to improper control of code generation (CWE-94). The vulnerability allows a remote attacker to execute arbitrary commands on the underlying web server without requiring any prior authentication or user interaction. This is classified as a high-priority injection flaw (OWASP A3) that can lead to a complete compromise of the confidentiality, integrity, and availability of the affected system. The issue is resolved in version 2.1.47.
Affected products
- Creative Themes Blocksy Companion Pro <= 2.1.46
Timeline
- 2026-06-19: other: Reported by Nguyen Ba Khanh
- 2026-06-29: disclosed: Initial disclosure by Patchstack
- 2026-06-29: patched: Version 2.1.47 released to address the vulnerability
- 2026-07-02: advisory: NVD publication date