plugin

Blocksy Companion Pro Vulnerabilities

5 known security issues reported for the Blocksy Companion Pro WordPress plugin. Most recent disclosed Jun 29, 2026.

1 critical 2 high 2 medium

Running Blocksy Companion Pro on your site? Check whether your installed version is affected.

Scan your site free

Blocksy Companion Pro <= 2.1.46 - Unauthenticated Remote Code Execution

critical

The Blocksy Companion Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.46. This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 2.1.46
Fixed in:
2.1.47
Disclosed:
Jun 29, 2026

CVE-2026-57624 on NVD →

Blocksy Companion Pro <= 2.1.45 - Authenticated (Contributor+) Remote Code Execution

high

The Blocksy Companion Pro plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.1.45. This is due to insufficient validation of user supplied input before it is executed. This makes it possible for authenticated attackers, with contributor-level access and above, to execute arb...

CVSS:
8.8
Affected:
up to 2.1.45
Fixed in:
2.1.46
Disclosed:
Jun 26, 2026

CVE-2026-57315 on NVD →

Blocksy Companion Pro <= 2.1.46 - Unauthenticated Insecure Direct Object Reference

medium

The Blocksy Companion Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.46 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform unauthorized actions.

CVSS:
5.3
Affected:
up to 2.1.46
Fixed in:
2.1.47
Disclosed:
Jun 26, 2026

CVE-2026-57630 on NVD →

Blocksy Companion Pro <= 2.1.37 - Authenticated (Contributor+) Remote Code Execution

medium

The Blocksy Companion Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.37. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

CVSS:
4.3
Affected:
up to 2.1.37
Fixed in:
2.1.38
Disclosed:
Apr 22, 2026

CVE-2026-40783 on NVD →

Blocksy Companion Pro < 2.1.29 - Unauthenticated SQL Injection

high

The Blocksy Companion Pro plugin for WordPress is vulnerable to SQL Injection in versions up to 2.1.29 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alre...

CVSS:
7.5
Affected:
up to 2.1.29
Fixed in:
2.1.29
Disclosed:
Apr 8, 2026

CVE-2026-39596 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database