PT-2026-56760 · WordPress · Blocksy Companion

CVE-2026-15158

·

Published

2026-07-01

·

Updated

2026-08-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Blocksy Companion versions prior to 2.1.47
Description The Blocksy Companion plugin for WordPress allows unauthenticated arbitrary file upload through the save attachments() function. The issue occurs because the Custom Fonts extension uses a wp check filetype and ext filter that validates filenames using strpos() to check for .woff2 or .ttf substrings instead of verifying the final extension via PATHINFO EXTENSION. This flaw enables attackers to bypass MIME validation using double-extension filenames, such as shell.woff2.php, leading to potential remote code execution. This issue is only exploitable when the premium version (blocksy-companion-pro) is installed and both the WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions are active. The vulnerability is triggered via the blc-review-images[] parameter.
Recommendations Update Blocksy Companion to version 2.1.47 or later. As a temporary workaround, deactivate the Custom Fonts or WooCommerce Extra (Advanced Reviews) extensions within the premium plugin to eliminate the vulnerable code paths.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15158

Affected Products

Blocksy Companion