CVE-2026-15158: pre-auth arbitrary file upload in creativethemeshq Blocksy Companion

Unauthenticated attackers can upload malicious files to websites running certain configurations of the Blocksy Companion plugin, potentially achieving remote code execution; see CVE-2026-15158. The flaw affects the 2.x line through 2.1.46. Exploitation requires the commercial blocksy-companion-pro installation with both the Custom Fonts extension and the WooCommerce Extra (Advanced Reviews) extension active — the free plugin alone does not expose the vulnerable upload path.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.01067
CWE
CWE-434
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

High urgency: this allows unauthenticated uploads that can lead to RCE when the paid plugin plus two extensions are enabled — disable or remove those extensions until the vendor issues a patch.

What is CVE-2026-15158?

Unauthenticated attackers can upload malicious files to websites running certain configurations of the Blocksy Companion plugin, potentially achieving remote code execution; see CVE-2026-15158. The flaw affects the 2.x line through 2.1.46. Exploitation requires the commercial blocksy-companion-pro installation with both the Custom Fonts extension and the WooCommerce Extra (Advanced Reviews) extension active — the free plugin alone does not expose the vulnerable upload path. The weakness is classified as CWE-434 (Unrestricted File Upload).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of creativethemeshq Blocksy Companion are affected?

BRANCHAFFECTEDFIXED
2.x2.1.46 and earlier

Is CVE-2026-15158 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-15158

  1. Deactivate or uninstall blocksy-companion-pro and the Custom Fonts and WooCommerce Extra (Advanced Reviews) extensions until a vendor fix is available
  2. Restrict access to upload endpoints (require authentication or IP allowlists) and block direct placement of web-executable files
  3. Search logs and recent uploads for suspicious filenames with multiple extensions (for example files including .woff2 or .ttf and another extension) and remove any unrecognized uploads
  4. Apply vendor guidance and install official updates as soon as Creativethemeshq publishes fixed releases

Frequently asked questions

Is CVE-2026-15158 being actively exploited?

There are no public reports of exploitation of CVE-2026-15158 as of 2026-09-29.

Which Blocksy Companion versions are affected by CVE-2026-15158?

The issue affects Blocksy Companion 2.x releases up to and including version 2.1.46.

Is there a patch for CVE-2026-15158?

No fixed versions are listed in the provided data; monitor vendor announcements and do not re-enable the implicated extensions until a patch is released.

Does CVE-2026-15158 require authentication?

No, exploitation does not require authentication, but it only succeeds when the paid blocksy-companion-pro plugin and the specified extensions are active.

References