🧱 Blocksy Companion Pro plugin has a CVSS 10 unauthenticated RCE flaw. No login needed to execute code on your site. If you're on <= 2.1.46, update immediately. CVE-2026-57624 https://secalerts.co/vulnerability/CVE-2026-57624?utm_campaign=x https://t.co/fxWi6Q1js7
Post summary
A critical CVSS 10 unauthenticated RCE flaw (CVE‑2026‑57624) has been disclosed in Blocksy Companion Pro plugin. Users on version 2.1.46 or earlier are urged to update immediately.
🚨 CRITICAL - Unauthenticated Remote Code Execution in Blocksy Companion Pro (CVE-2026-57624)
CVE-2026-57624 is an unauthenticated RCE affecting the WordPress plugin Blocksy Companion Pro, allowing arbitrary code execution via the plugin’s code-generation functionality. The root cause is improper control of code generation (code injection), enabling attacker-supplied input to be transformed into executable code. An attacker can exploit this remotely over HTTP by sending crafted requests to vulnerable plugin endpoints without needing authentication, making internet-exposed WordPress sites prime targets. Successful exploitation can lead to full site compromise, webshell deployment, data theft, and lateral movement by executing code with the web server’s privileges.
👉 Affected: Blocksy Companion Pro <= 2.1.46 | Upgrade to a fixed release newer than 2.1.46 (vendor patch required)
Post summary
The post announces a critical unauthenticated RCE in Blocksy Companion Pro, details the vulnerability vector, and advises users to upgrade to a patched version.