CVE-2026-58480 Details
Description
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.
A vulnerability allowing unauthenticated arbitrary file uploads has been identified in the Blocksy Companion Pro plugin for WordPress, in versions prior to 2.1.47. This vulnerability arises from inadequate extension validation in the save_attachments function, part of the Advanced Reviews feature. Attackers can exploit this flaw by uploading executable files with double-extension names, such as shell.woff2.php, which bypass the validation and are executed by the web server as PHP files, leading to remote code execution.
Users of the Blocksy Companion Pro WordPress plugin should update to version 2.1.47 or later. Patchstack users can enable auto-updates for vulnerable plugins.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 8, 2026CISA-ADP
Assessed Jul 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Blocksy Companion | <= 2.1.46 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | New CVE Received | [email protected] |
| Jul 8, 2026 | CVE Modified | CISA-ADP |
Volerion