Blocksy Companion WordPress Plugin Arbitrary File Upload Vulnerability

Vulnerability

A vulnerability allowing arbitrary file upload has been identified in the Blocksy Companion plugin for WordPress, affecting all versions through 2.1.46. The issue arises in the save_attachments function, where the Custom Fonts extension improperly validates file types. It allows double-extension filenames, such as shell.woff2.php, to bypass MIME checks and be uploaded as executable files. This vulnerability is exploitable by unauthenticated users when the premium version of the plugin is active, along with the WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions.

Impact

Exploitation of this vulnerability allows for arbitrary file upload, with the potential for uploaded files to be executed, leading to remote code execution.

Reproduction

To reproduce this vulnerability, install the Blocksy Companion plugin (premium version) and activate the Custom Fonts and WooCommerce Extra (Advanced Reviews) extensions. Once this setup is complete, upload a file through a review image parameter, using a double-extension filename that includes .woff2 or .ttf. The file will bypass validation and can be executed on the server.

Remediation

Users are advised to update the Blocksy Companion plugin to version 2.1.47 or a newer patched version.

Added: Jul 9, 2026, 10:27 AM
Updated: Jul 9, 2026, 10:27 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
7.5
exploitability
8.9
remediation
7.7
relevance
9.2
threat
4.8
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.