← back
CVE-2026-58480criticalobserved exploitationCWE-434

Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments

70Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 9.2epss 3.6%
from disclosure to weapon18 days
Published on NVDJul 8
1st PoC+18d
VulnCheckJul 2
exploitation probability
3.6%top 11% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.