Junglewise Threat Intelligence

CVE-2026-57624: Creative Themes Blocksy Companion Pro unauthenticated RCE

CVE-2026-57624 · Severity: critical · CVSS 10 · Published 2026-07-02

Technologies: Creative Themes Blocksy Companion Pro. Vendors: Creative Themes.

Executive brief

Blocksy Companion Pro is a premium WordPress plugin used to extend the functionality of the Blocksy theme. A critical security flaw allows an unauthenticated attacker to remotely execute code on the website's server. This could lead to a total takeover of the website, theft of customer data, or the installation of malware, potentially impacting the business's reputation and operational continuity.

Technical details

The Blocksy Companion Pro plugin for WordPress is vulnerable to unauthenticated Remote Code Execution (RCE) due to improper control of code generation (CWE-94). The vulnerability allows a remote attacker to execute arbitrary commands on the underlying web server without requiring any prior authentication or user interaction. This is classified as a high-priority injection flaw (OWASP A3) that can lead to a complete compromise of the confidentiality, integrity, and availability of the affected system. The issue is resolved in version 2.1.47.

Affected products

  • Creative Themes Blocksy Companion Pro <= 2.1.46

Timeline

  • 2026-06-19: other: Reported by Nguyen Ba Khanh
  • 2026-06-29: disclosed: Initial disclosure by Patchstack
  • 2026-06-29: patched: Version 2.1.47 released to address the vulnerability
  • 2026-07-02: advisory: NVD publication date

References

Related threats