Blocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter
critical
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring v...
- CVSS:
- 9.8
- Affected:
- up to 2.1.46
- Fixed in:
- 2.1.47
- Disclosed:
- Jul 1, 2026
CVE-2026-15158 on NVD →
Blocksy Companion <= 2.1.45 - Authenticated (Editor+) Stored Cross-Site Scripting via 'product_description' Parameter
medium
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbit...
- CVSS:
- 4.4
- Affected:
- up to 2.1.45
- Fixed in:
- 2.1.46
- Disclosed:
- Jun 18, 2026
CVE-2026-12430 on NVD →
Blocksy Companion <= 2.1.19 - Authenticated (Author+) Arbitrary File Upload via SVG Upload Bypass
high
The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2.1.19. This is due to insufficient file type validation detecting SVG files, allowing double extension files to bypass sanitization while being accepted as a valid SVG file. This makes...
- CVSS:
- 8.8
- Affected:
- up to 2.1.19
- Fixed in:
- 2.1.20
- Disclosed:
- Nov 10, 2025
CVE-2025-12846 on NVD →
Blocksy Companion <= 2.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blocksy_newsletter_subscribe' shortcode in all versions up to, and including, 2.1.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 2.1.14
- Fixed in:
- 2.1.15
- Disclosed:
- Oct 6, 2025
CVE-2025-12475 on NVD →
Blocksy Companion <= 2.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via blocksy_newsletter_subscribe Shortcode
medium
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newsletter_subscribe shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at...
- CVSS:
- 6.4
- Affected:
- up to 2.1.10
- Fixed in:
- 2.1.11
- Disclosed:
- Sep 16, 2025
CVE-2025-9565 on NVD →
Blocksy Companion <= 2.0.42 - Authenticated (Admin+) Server-Side Request Forgery
medium
The Blocksy Companion plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.42. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application which can...
- CVSS:
- 5.5
- Affected:
- up to 2.0.42
- Fixed in:
- 2.0.43
- Disclosed:
- May 30, 2024
CVE-2024-35633 on NVD →
Blocksy Companion <= 2.0.45 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Uploads
medium
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG uploads in versions up to, and including, 2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitra...
- CVSS:
- 6.4
- Affected:
- up to 2.0.45
- Fixed in:
- 2.0.46
- Disclosed:
- May 10, 2024
CVE-2024-4487 on NVD →
Blocksy Companion <= 2.0.28 - Cross-Site Request Forgery
medium
The Blocksy Companion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.28. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request grante...
- CVSS:
- 5.3
- Affected:
- up to 2.0.28
- Fixed in:
- 2.0.29
- Disclosed:
- Apr 10, 2024
CVE-2024-31932 on NVD →
Blocksy Companion <= 2.0.31 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contribu...
- CVSS:
- 6.4
- Affected:
- up to 2.0.31
- Fixed in:
- 2.0.32
- Disclosed:
- Mar 21, 2024
CVE-2024-2392 on NVD →
Blocksy Companion <= 1.8.81 - Authenticated(Subscriber+) Sensitive Information Exposure via blocksy_posts shortcode
medium
The Blocksy Companion plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.8.81 via the blocksy_posts shortcode. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including draft posts.
- CVSS:
- 4.3
- Affected:
- up to 1.8.81
- Fixed in:
- 1.8.82
- Disclosed:
- Apr 10, 2023
CVE-2023-1911 on NVD →
Blocksy Companion <= 1.8.67 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_posts
shortcode in versions up to, and including, 1.8.67 due to insufficient input sanitization and output escaping on user supplied 'class' attribute. This makes it possible for authenticated attackers w...
- CVSS:
- 6.4
- Affected:
- up to 1.8.68
- Fixed in:
- 1.8.68
- Disclosed:
- Jan 27, 2023
CVE-2023-23898 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 1.8.20
- Fixed in:
- 1.8.20
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database