CVE-2026-58480

CRITICAL EXPLOITED

Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-58480 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including shinthink.

AI-analyzed exploit summary This PoC exploits CVE-2026-58480, an unauthenticated arbitrary file upload vulnerability in Blocksy Companion Pro < 2.1.47. The exploit bypasses file extension validation via a strpos() substring check in the Custom Fonts extension, allowing PHP code execution via double-extension filenames like shell.woff2.php.

Description

Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.

Exploits (1)

github WORKING POC
by shinthink · pythonpoc
https://github.com/shinthink/CVE-2026-58480

This PoC exploits CVE-2026-58480, an unauthenticated arbitrary file upload vulnerability in Blocksy Companion Pro < 2.1.47. The exploit bypasses file extension validation via a strpos() substring check in the Custom Fonts extension, allowing PHP code execution via double-extension filenames like shell.woff2.php.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Blocksy Companion Pro (WordPress plugin) versions < 2.1.47 with Advanced Reviews and Custom Fonts extensions active
No auth needed
Prerequisites: Blocksy Companion Pro < 2.1.47 · Advanced Reviews extension (WooCommerce Extra) enabled · Custom Fonts extension enabled · Target must allow file uploads to wp-content/uploads/
mistral-large-3 · analyzed Jul 26, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0060
EPSS Percentile 45.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-07-02
CWE
CWE-434
Status published
Products (2)
Creative Themes/Blocksy Companion < 2.1.46
Creative Themes/Blocksy Companion 2.1.47
Published Jul 08, 2026
Tracked Since Jul 08, 2026