Executive brief
Blocksy Companion Pro is a premium WordPress plugin that extends the functionality of the Blocksy theme with advanced site-building features. A security flaw allows unauthorized individuals to potentially access sensitive information or interact with internal data by manipulating object identifiers. This could lead to the exposure of private site content or configuration details without requiring a login.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the Blocksy Companion Pro plugin for WordPress (versions <= 2.1.46). The flaw stems from insufficient authorization checks when accessing specific objects or data via user-controlled input. An unauthenticated remote attacker can exploit this by modifying parameters (such as IDs) in requests to the web server to access or interact with resources they are not authorized to view. This is classified under CWE-639 (Authorization Bypass Through User-Controlled Key). The vulnerability is resolved in version 2.1.47.
Affected products
- Creative Themes Blocksy Companion Pro <= 2.1.46
Timeline
- 2026-06-21: other: Reported by Austin Ginder
- 2026-06-26: advisory: Published by Patchstack and NVD
- 2026-06-26: patched: Patch released in version 2.1.47