CVE-2026-57624Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-02: 2Patch / Workaround · 2026-07-02: 2Technical Details · 2026-07-02: 207-02
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • SecAlerts@SecAlertsCo
    Disclosure

    🧱 Blocksy Companion Pro plugin has a CVSS 10 unauthenticated RCE flaw. No login needed to execute code on your site. If you're on &lt;= 2.1.46, update immediately. CVE-2026-57624 https://secalerts.co/vulnerability/CVE-2026-57624?utm_campaign=x https://t.co/fxWi6Q1js7

    Post summary

    A critical CVSS 10 unauthenticated RCE flaw (CVE‑2026‑57624) has been disclosed in Blocksy Companion Pro plugin. Users on version 2.1.46 or earlier are urged to update immediately.

    0000079
    846 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Unauthenticated Remote Code Execution in Blocksy Companion Pro (CVE-2026-57624) CVE-2026-57624 is an unauthenticated RCE affecting the WordPress plugin Blocksy Companion Pro, allowing arbitrary code execution via the plugin’s code-generation functionality. The root cause is improper control of code generation (code injection), enabling attacker-supplied input to be transformed into executable code. An attacker can exploit this remotely over HTTP by sending crafted requests to vulnerable plugin endpoints without needing authentication, making internet-exposed WordPress sites prime targets. Successful exploitation can lead to full site compromise, webshell deployment, data theft, and lateral movement by executing code with the web server’s privileges. 👉 Affected: Blocksy Companion Pro <= 2.1.46 | Upgrade to a fixed release newer than 2.1.46 (vendor patch required)

    Post summary

    The post announces a critical unauthenticated RCE in Blocksy Companion Pro, details the vulnerability vector, and advises users to upgrade to a patched version.

    00000112
    232 followersView on X

Explore more