PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-58480 Creative Themes CVE debrief

The Blocksy Companion Pro plugin for WordPress contains an unauthenticated file-upload vulnerability, allowing attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames, such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution. This issue is considered critical, with a CVSS score of 9.2, and affects WordPress sites with the Blocksy Companion Pro plugin installed.

Vendor
Creative Themes
Product
Blocksy Companion
CVSS
CRITICAL 9.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-08
Original CVE updated
2026-07-08
Advisory published
2026-07-08
Advisory updated
2026-07-08

Who should care

Administrators and users of WordPress sites with the Blocksy Companion Pro plugin installed should be aware of this vulnerability and take immediate action to protect their sites. This includes updating the plugin to version 2.1.47 or later, restricting access to the Advanced Reviews feature, and implementing additional security measures such as web application firewalls and intrusion detection systems.

Technical summary

The vulnerability exists due to insufficient validation of user input in the plugin's save_attachments function. Attackers can exploit this by uploading double-extension filenames, allowing them to bypass security checks and execute files as PHP, leading to remote code execution. The Custom Fonts extension's flawed strpos() substring check is a key factor in this vulnerability, as it allows attackers to craft filenames that pass validation but are executed as PHP code.

Defensive priority

High

Recommended defensive actions

  • Update the Blocksy Companion Pro plugin to version 2.1.47 or later.
  • Restrict access to the Advanced Reviews feature to authenticated users only.
  • Implement additional security measures, such as web application firewalls and intrusion detection systems, to monitor and block suspicious traffic.
  • Regularly review and update plugins and themes to ensure they are up-to-date and secure.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability was reported by Patchstack and is tracked as CVE-2026-58480. The NVD entry is currently Deferred. Evidence of exploitation has not been reported, but defenders should verify logs for suspicious activity related to file uploads and execution. The Blocksy Companion Pro plugin's Advanced Reviews feature is particularly vulnerable, and users should focus on securing this functionality.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-58480 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-58480

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-58480 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58480

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://patchstack.com/database/wordpress/plugin/blocksy-companion/vulnerability/wordpress-blocksy-companion-plugin-2-1-46-unauthenticated-arbitrary-file-upload-vulnerability

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://wordpress.org/plugins/blocksy-companion/

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/blocksy-companion-pro-unauthenticated-file-upload-via-save-attachments

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blocksy-companion/blocksy-companion-2146-unauthenticated-arbitrary-file-upload-via-blc-review-images-parameter

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.