DIRAS TAKE
Urgent: public exploit code exists for this unauthenticated RCE, so reduce exposure immediately by disabling the Advanced Reviews upload functionality or removing the plugin until a vendor patch is applied.
What is CVE-2026-58480?
Attackers can upload and execute arbitrary files on sites running the Blocksy Companion plugin, enabling remote code execution. CVE-2026-58480 affects Blocksy Companion 2.x, specifically 2.1.46 and earlier. The flaw is an unauthenticated file upload validation bypass in the save_attachments handler exposed via the Advanced Reviews feature; attackers can submit specially crafted filenames (for example double extensions) to bypass extension checks and have the server execute uploaded PHP. No authentication or user interaction is required beyond network access to the vulnerable endpoint. The weakness is classified as CWE-434 (Unrestricted File Upload).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Creative Themes Blocksy Companion are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2.x | 2.1.46 and earlier |
Is CVE-2026-58480 being exploited?
Public exploit code is available.
How to fix CVE-2026-58480
- Follow the vendor advisory and apply the vendor patch as soon as a fixed release is published.
- Temporarily disable the Advanced Reviews feature or any upload endpoints exposed by Blocksy Companion.
- Remove or deactivate the Blocksy Companion plugin from internet‑facing sites if patching is delayed.
- Harden web server upload handling: block execution in upload directories and monitor webserver and application logs for suspicious uploads or requests.
Frequently asked questions
Is CVE-2026-58480 being actively exploited?
Public exploit code is available for CVE-2026-58480.
Which Blocksy Companion versions are affected by CVE-2026-58480?
Blocksy Companion 2.x releases are affected; the advisory lists versions 2.1.46 and earlier as vulnerable.
Is there a patch for CVE-2026-58480?
A patch is reported available by the vendor, but the facts do not list a specific fixed version; apply the vendor update when it is published.
Does CVE-2026-58480 require authentication?
No, the vulnerability is an unauthenticated file upload bypass and does not require valid credentials.
References
- nvd.nist.gov/vuln/detail/CVE-2026-58480
- cve.org/CVERecord?id=CVE-2026-58480
- wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blocksy-companion/blocksy-companion-2146-unauthenticated-arbitrary-file-upload-via-blc-review-images-parameter
- patchstack.com/database/wordpress/plugin/blocksy-companion/vulnerability/wordpress-blocksy-companion-plugin-2-1-46-unauthenticated-arbitrary-file-upload-vulnerability
- wordpress.org/plugins/blocksy-companion
- vulncheck.com/advisories/blocksy-companion-pro-unauthenticated-file-upload-via-save-attachments
- All Creative Themes CVEs on CVE Radar
- CVEs published in September 2026