CVE-2026-58480General

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-07-08); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-08: 2Mentions · 2026-07-09: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-09: 107-0807-09
Signal classification3 categories
General
133.3%
Patch
133.3%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-082
General1Patch1
2026-07-091
Disclosure1
Full discourse3 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-58480 — CVSS 9.8/10 ██████████ Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/WPcbSFQm1x

    Post summary

    A critical unauthenticated arbitrary file upload vulnerability (CVE-2026-58480) in Blocksy Companion Pro for WordPress has been disclosed with a high CVSS score, and a patch is now available.

    10001109
    64 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🔐 CVE-2026-58480 — Blocksy Companion Unrestricted File Upload RCE (CVSS 9.8) 🔗 https://threataft.com/articles/blocksy-companion-file-upload-rce-cve-2026-58480?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #ThreatIntel

    Post summary

    The tweet announces CVE-2026-58480 – a high‑severity RCE via unrestricted file upload in Blocksy Companion and links to a detailed article.

    0000063
    34 followersView on X
  • MalwareObserver@MalwareObserver
    General

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-58480](https://patchstack.com/database/wordpress/plugin/blocksy-companion/vulnerability... https://patchstack.com/database/wordpress/plugin/blocksy-companion/vulnerability/wordpress-blocksy-companion-plugin-2-1-46-unauthenticated-arbitr

    Post summary

    A brief notification of CVE‑2026‑58480 with a link to a PatchStack article; the post contains no actionable or detailed information.

    0000035
    9 followersView on X

Explore more