Junglewise Threat Intelligence

CVE-2026-57630: Creative Themes Blocksy Companion Pro IDOR vulnerability

CVE-2026-57630 · Severity: medium · CVSS 5.3 · Published 2026-06-26

Technologies: Creative Themes Blocksy Companion Pro. Vendors: Creative Themes.

Executive brief

Blocksy Companion Pro is a premium WordPress plugin that extends the functionality of the Blocksy theme with advanced site-building features. A security flaw allows unauthorized individuals to potentially access sensitive information or interact with internal data by manipulating object identifiers. This could lead to the exposure of private site content or configuration details without requiring a login.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the Blocksy Companion Pro plugin for WordPress (versions <= 2.1.46). The flaw stems from insufficient authorization checks when accessing specific objects or data via user-controlled input. An unauthenticated remote attacker can exploit this by modifying parameters (such as IDs) in requests to the web server to access or interact with resources they are not authorized to view. This is classified under CWE-639 (Authorization Bypass Through User-Controlled Key). The vulnerability is resolved in version 2.1.47.

Affected products

  • Creative Themes Blocksy Companion Pro <= 2.1.46

Timeline

  • 2026-06-21: other: Reported by Austin Ginder
  • 2026-06-26: advisory: Published by Patchstack and NVD
  • 2026-06-26: patched: Patch released in version 2.1.47

References

Related threats