• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-58480: pre-auth remote code execution in Creative Themes Blocksy Companion

Attackers can upload and execute arbitrary files on sites running the Blocksy Companion plugin, enabling remote code execution. CVE-2026-58480 affects Blocksy Companion 2.x, specifically 2.1.46 and earlier. The flaw is an unauthenticated file upload validation bypass in the save_attachments handler exposed via the Advanced Reviews feature; attackers can submit specially crafted filenames (for example double extensions) to bypass extension checks and have the server execute uploaded PHP. No authentication or user interaction is required beyond network access to the vulnerable endpoint.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.03572
CWE
CWE-434
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists for this unauthenticated RCE, so reduce exposure immediately by disabling the Advanced Reviews upload functionality or removing the plugin until a vendor patch is applied.

What is CVE-2026-58480?

Attackers can upload and execute arbitrary files on sites running the Blocksy Companion plugin, enabling remote code execution. CVE-2026-58480 affects Blocksy Companion 2.x, specifically 2.1.46 and earlier. The flaw is an unauthenticated file upload validation bypass in the save_attachments handler exposed via the Advanced Reviews feature; attackers can submit specially crafted filenames (for example double extensions) to bypass extension checks and have the server execute uploaded PHP. No authentication or user interaction is required beyond network access to the vulnerable endpoint. The weakness is classified as CWE-434 (Unrestricted File Upload).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Creative Themes Blocksy Companion are affected?

BRANCHAFFECTEDFIXED
2.x2.1.46 and earlier

Is CVE-2026-58480 being exploited?

Public exploit code is available.

How to fix CVE-2026-58480

  1. Follow the vendor advisory and apply the vendor patch as soon as a fixed release is published.
  2. Temporarily disable the Advanced Reviews feature or any upload endpoints exposed by Blocksy Companion.
  3. Remove or deactivate the Blocksy Companion plugin from internet‑facing sites if patching is delayed.
  4. Harden web server upload handling: block execution in upload directories and monitor webserver and application logs for suspicious uploads or requests.

Frequently asked questions

Is CVE-2026-58480 being actively exploited?

Public exploit code is available for CVE-2026-58480.

Which Blocksy Companion versions are affected by CVE-2026-58480?

Blocksy Companion 2.x releases are affected; the advisory lists versions 2.1.46 and earlier as vulnerable.

Is there a patch for CVE-2026-58480?

A patch is reported available by the vendor, but the facts do not list a specific fixed version; apply the vendor update when it is published.

Does CVE-2026-58480 require authentication?

No, the vulnerability is an unauthenticated file upload bypass and does not require valid credentials.

References