Impact
An unauthenticated Remote Code Execution flaw exists in Blocksy Companion Pro plugin versions 2.1.46 and earlier. Based on the description, it is inferred that the plugin processes input from external requests without proper validation, enabling an attacker to execute arbitrary code. This compromise can affect the confidentiality, integrity, and availability of the WordPress site and any data it hosts. The weakness is classified as CWE-94.
Affected Systems
WordPress installations that use the Creative Themes Blocksy Companion Pro plugin with version 2.1.46 or earlier are affected. The issue is tied to the plugin’s code base, and no specific server configuration or additional theme is required for exploitation.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. The EPSS score of < 1% shows a low but non-zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the flaw is described as unauthenticated and remote, it is inferred that an attacker could exploit it via unauthenticated HTTP requests to the vulnerable plugin, allowing arbitrary code execution. This presents a significant risk to any affected WordPress installation.
OpenCVE Enrichment