PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8365 creativethemeshq CVE debrief

The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V200 database migration in versions up to and including 2.1.35. This is due to insufficient input sanitization in the blocksy_sanitize_post_meta_options() function, which only blocks values containing '<' or '>' and does not prevent serialized PHP object strings from being stored in post meta, combined with the SearchReplacer::run_recursively() function unconditionally deserializing all string values via @unserialize() during migration without restricting allowed classes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a serialized Blocksy RaiiPattern object into post meta that, when the V200 migration runs on an upgraded site, is deserialized and triggers RaiiPattern::__destruct(), which executes arbitrary PHP callables via call_user_func().

Vendor
creativethemeshq
Product
Blocksy
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-09
Original CVE updated
2026-06-09
Advisory published
2026-06-09
Advisory updated
2026-06-09

Who should care

Users of the Blocksy theme for WordPress, particularly those with contributor-level access and above, should be aware of this vulnerability and take steps to mitigate it.

Technical summary

The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. It is caused by a combination of insufficient input sanitization and unconditional deserialization of string values during database migration.

Defensive priority

high

Recommended defensive actions

  • Update the Blocksy theme to a version that fixes the vulnerability.
  • Restrict access to the 'blocksy_meta' REST API field.
  • Implement additional input sanitization and validation.

Evidence notes

Evidence for this vulnerability comes from the NVD and Wordfence security research.

Official resources

CVE-2026-8365 was published on 2026-06-09T09:16:31.013Z and modified on 2026-06-09T13:33:34.393Z.