Blocksy Companion Pro <= 2.1.46 - Unauthenticated Remote Code Execution
critical
The Blocksy Companion Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.46. This makes it possible for unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 2.1.46
- Fixed in:
- 2.1.47
- Disclosed:
- Jun 29, 2026
CVE-2026-57624 on NVD →
Blocksy Companion Pro <= 2.1.45 - Authenticated (Contributor+) Remote Code Execution
high
The Blocksy Companion Pro plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.1.45. This is due to insufficient validation of user supplied input before it is executed. This makes it possible for authenticated attackers, with contributor-level access and above, to execute arb...
- CVSS:
- 8.8
- Affected:
- up to 2.1.45
- Fixed in:
- 2.1.46
- Disclosed:
- Jun 26, 2026
CVE-2026-57315 on NVD →
Blocksy Companion Pro <= 2.1.46 - Unauthenticated Insecure Direct Object Reference
medium
The Blocksy Companion Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.46 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform unauthorized actions.
- CVSS:
- 5.3
- Affected:
- up to 2.1.46
- Fixed in:
- 2.1.47
- Disclosed:
- Jun 26, 2026
CVE-2026-57630 on NVD →
Blocksy Companion Pro <= 2.1.37 - Authenticated (Contributor+) Remote Code Execution
medium
The Blocksy Companion Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.37. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
- CVSS:
- 4.3
- Affected:
- up to 2.1.37
- Fixed in:
- 2.1.38
- Disclosed:
- Apr 22, 2026
CVE-2026-40783 on NVD →
Blocksy Companion Pro < 2.1.29 - Unauthenticated SQL Injection
high
The Blocksy Companion Pro plugin for WordPress is vulnerable to SQL Injection in versions up to 2.1.29 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alre...
- CVSS:
- 7.5
- Affected:
- up to 2.1.29
- Fixed in:
- 2.1.29
- Disclosed:
- Apr 8, 2026
CVE-2026-39596 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database