Impact
An unauthenticated Remote Code Execution flaw exists in Blocksy Companion Pro plugin versions 2.1.46 and earlier. Based on the description, it is inferred that the attacker can send specially crafted input to the plugin’s endpoints, which the plugin processes without proper validation, allowing arbitrary code. This can compromise the confidentiality, integrity, and availability of the website and any data it hosts. The weakness is categorized as CWE-94.
Affected Systems
WordPress installations that employ the Creative Themes Blocksy Companion Pro plugin with a version of 2.1.46 or earlier are is tied to the plugin’s code base, and the description does not indicate any dependence on particular server configurations or WordPress themes.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity. Based on the provided data, it is inferred that exploitation is feasible because the flaw is unauthenticated, meaning no credentials are required if the attacker can reach the vulnerable endpoint. The EPSS score is less than 1 %, and the vulnerability is not listed in the CISA KEV catalog; however, the combination of remote access, zero‑auth, and high severity suggests a potentially serious risk to exposed sites.
OpenCVE Enrichment