PT-2026-56760 · WordPress · Blocksy Companion
CVE-2026-15158
·
Published
2026-07-01
·
Updated
2026-08-21
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Blocksy Companion versions prior to 2.1.47
Description
The Blocksy Companion plugin for WordPress allows unauthenticated arbitrary file upload through the
save attachments() function. The issue occurs because the Custom Fonts extension uses a wp check filetype and ext filter that validates filenames using strpos() to check for .woff2 or .ttf substrings instead of verifying the final extension via PATHINFO EXTENSION. This flaw enables attackers to bypass MIME validation using double-extension filenames, such as shell.woff2.php, leading to potential remote code execution. This issue is only exploitable when the premium version (blocksy-companion-pro) is installed and both the WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions are active. The vulnerability is triggered via the blc-review-images[] parameter.Recommendations
Update Blocksy Companion to version 2.1.47 or later.
As a temporary workaround, deactivate the Custom Fonts or WooCommerce Extra (Advanced Reviews) extensions within the premium plugin to eliminate the vulnerable code paths.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blocksy Companion