Description
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
Published: 2026-07-02
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated Remote Code Execution flaw exists in Blocksy Companion Pro plugin versions 2.1.46 and earlier. Based on the description, it is inferred that the attacker can send specially crafted input to the plugin’s endpoints, which the plugin processes without proper validation, allowing arbitrary code. This can compromise the confidentiality, integrity, and availability of the website and any data it hosts. The weakness is categorized as CWE-94.

Affected Systems

WordPress installations that employ the Creative Themes Blocksy Companion Pro plugin with a version of 2.1.46 or earlier are is tied to the plugin’s code base, and the description does not indicate any dependence on particular server configurations or WordPress themes.

Risk and Exploitability

The CVSS score of 10 indicates a critical severity. Based on the provided data, it is inferred that exploitation is feasible because the flaw is unauthenticated, meaning no credentials are required if the attacker can reach the vulnerable endpoint. The EPSS score is less than 1 %, and the vulnerability is not listed in the CISA KEV catalog; however, the combination of remote access, zero‑auth, and high severity suggests a potentially serious risk to exposed sites.

Generated by OpenCVE AI on July 21, 2026 at 11:45 UTC.

Remediation

Vendor Solution

Update the WordPress Blocksy Companion Plugin to the latest available version (at least 2.1.47).


OpenCVE Recommended Actions

  • Update the Blocksy Companion Pro plugin to version 2.1.47 or newer.
  • If a patch cannot be applied immediately, uninstall or temporarily deactivate the plugin to remove the vulnerability.
  • Apply a web application firewall rule or network filter to block HTTP requests targeting the vulnerable plugin endpoints until the update is deployed.

Generated by OpenCVE AI on July 21, 2026 at 11:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
Title WordPress Blocksy Companion Pro plugin <= 2.1.46 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T19:39:14.229Z

Reserved: 2026-06-25T08:03:02.838Z

Link: CVE-2026-57624

cve-icon Vulnrichment

Updated: 2026-07-02T19:39:08.279Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:00:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')