DIRAS TAKE
High urgency: this allows unauthenticated uploads that can lead to RCE when the paid plugin plus two extensions are enabled — disable or remove those extensions until the vendor issues a patch.
What is CVE-2026-15158?
Unauthenticated attackers can upload malicious files to websites running certain configurations of the Blocksy Companion plugin, potentially achieving remote code execution; see CVE-2026-15158. The flaw affects the 2.x line through 2.1.46. Exploitation requires the commercial blocksy-companion-pro installation with both the Custom Fonts extension and the WooCommerce Extra (Advanced Reviews) extension active — the free plugin alone does not expose the vulnerable upload path. The weakness is classified as CWE-434 (Unrestricted File Upload).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of creativethemeshq Blocksy Companion are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2.x | 2.1.46 and earlier |
Is CVE-2026-15158 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-15158
- Deactivate or uninstall blocksy-companion-pro and the Custom Fonts and WooCommerce Extra (Advanced Reviews) extensions until a vendor fix is available
- Restrict access to upload endpoints (require authentication or IP allowlists) and block direct placement of web-executable files
- Search logs and recent uploads for suspicious filenames with multiple extensions (for example files including .woff2 or .ttf and another extension) and remove any unrecognized uploads
- Apply vendor guidance and install official updates as soon as Creativethemeshq publishes fixed releases
Frequently asked questions
Is CVE-2026-15158 being actively exploited?
There are no public reports of exploitation of CVE-2026-15158 as of 2026-09-29.
Which Blocksy Companion versions are affected by CVE-2026-15158?
The issue affects Blocksy Companion 2.x releases up to and including version 2.1.46.
Is there a patch for CVE-2026-15158?
No fixed versions are listed in the provided data; monitor vendor announcements and do not re-enable the implicated extensions until a patch is released.
Does CVE-2026-15158 require authentication?
No, exploitation does not require authentication, but it only succeeds when the paid blocksy-companion-pro plugin and the specified extensions are active.
References
- nvd.nist.gov/vuln/detail/CVE-2026-15158
- cve.org/CVERecord?id=CVE-2026-15158
- wordfence.com/threat-intel/vulnerabilities/id/2df449b4-3f3b-4afc-b391-8d8d11710c07?source=cve
- plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.46/framework/premium/extensions/woocommerce-extra/features/advanced-reviews/feature.php#L811
- plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.46/framework/premium/extensions/custom-fonts/extension.php#L137
- All creativethemeshq CVEs on CVE Radar
- CVEs published in September 2026