Blocksy Companion Pro WordPress Plugin Unauthenticated Arbitrary File Upload Vulnerability

Vulnerability

A vulnerability allowing unauthenticated arbitrary file uploads has been identified in the Blocksy Companion Pro plugin for WordPress, in versions prior to 2.1.47. This vulnerability arises from inadequate extension validation in the save_attachments function, part of the Advanced Reviews feature. Attackers can exploit this flaw by uploading executable files with double-extension names, such as shell.woff2.php, which bypass the validation and are executed by the web server as PHP files, leading to remote code execution.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, which could include executable files like web shells, potentially leading to remote code execution on the server.

Reproduction

To reproduce this vulnerability, upload a file through the Advanced Reviews feature while the Blocksy Companion Pro plugin is active, along with the Custom Fonts and WooCommerce Extra extensions. Use a double-extension filename that includes '.woff2' or '.ttf' to bypass the file type validation. The uploaded file will be executed on the server as a PHP script, achieving remote code execution.

Remediation

Users of the Blocksy Companion Pro WordPress plugin should update to version 2.1.47 or later. Patchstack users can enable auto-updates for vulnerable plugins.

Added: Jul 8, 2026, 2:29 PM
Updated: Jul 8, 2026, 2:29 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
7.5
exploitability
6.8
remediation
7.9
relevance
9.7
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.