CVE-2026-58480 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-58480 requires immediate attention.

· 6 min read

Executive Summary

CVE-2026-58480 is a critical unauthenticated file upload flaw in Blocksy Companion Pro for WordPress before 2.1.47. An attacker can abuse the Advanced Reviews feature and the save_attachments function to upload executable files by bypassing extension validation. The issue is especially dangerous because the Custom Fonts extension uses a flawed strpos() substring check, allowing double-extension payloads such as shell.woff2.php to pass validation and execute as PHP on the server.

For solo developers and small teams, this is a high-priority patch-now issue: if your site uses Blocksy Companion Pro, assume public exposure until proven otherwise. Even though this vulnerability is not currently known to be exploited in the wild and is not in CISA KEV, the attack path is straightforward and the impact is full remote code execution.

Immediate Action

  • Upgrade Blocksy Companion Pro to 2.1.47 or later immediately. If you cannot patch right away, disable the plugin and any features tied to Advanced Reviews and Custom Fonts.
  • Temporarily isolate the site behind maintenance mode, IP allowlisting, or a WAF rule that blocks file uploads to WordPress endpoints until patched.
  • Search for suspicious uploads in wp-content/uploads/ and related plugin directories, especially files with double extensions like *.php.jpg, *.php.woff2, or *.woff2.php.
  • Review web server execution rules to ensure PHP is not executable in upload directories.
  • Rotate credentials if you find any sign of compromise, including admin accounts, database credentials, and API keys.
  • Vendor advisory: Blocksy / vendor security advisory (replace with official notice if available).

Affected Versions

  • blocksy-companion-pro@<2.1.47 vulnerable
  • blocksy-companion-pro@2.1.47+ safe
  • If you are unsure which version is installed, treat the site as vulnerable until verified

Resolution Guide

WordPress / plugin update

wp plugin update blocksy-companion-pro
wp plugin get blocksy-companion-pro --field=version

If you manage WordPress with Composer (only if your stack packages the plugin this way):

composer show | grep -i blocksy
composer update

Linux package / deployment hardening

# Debian/Ubuntu: ensure PHP is not executed in uploads
sudo find /var/www -path '*/uploads/*' -type f \( -name '*.php' -o -name '*.phtml' -o -name '*.phar' \) -print

# Apache: block script execution in uploads
cat <<'EOF' | sudo tee /var/www/html/wp-content/uploads/.htaccess
<FilesMatch "\.(php|phtml|phar)$">
  Require all denied
</FilesMatch>
EOF

# Nginx: deny PHP execution in uploads
# add to server block:
# location ~* /wp-content/uploads/.*\.(php|phtml|phar)$ { deny all; }

Docker image guidance

# Rebuild with the patched plugin version baked in
docker build --no-cache -t your-wordpress:patched .

# Run the patched image
docker run -d --name wordpress-patched your-wordpress:patched

Config hardening

// wp-config.php
define('DISALLOW_FILE_EDIT', true);
define('WP_DEBUG', false);

Minimal code fix example if you maintain a fork or custom plugin logic:

// BAD: substring match can be bypassed
// if (strpos($filename, 'woff2') !== false) { ... }

// GOOD: strict extension allowlist
$allowed = ['woff2', 'woff', 'ttf', 'otf'];
$ext = strtolower(pathinfo($filename, PATHINFO_EXTENSION));
if (!in_array($ext, $allowed, true)) {
    return new WP_Error('invalid_file', 'Invalid file type');
}

Detection & Verification

Check the installed version

wp plugin get blocksy-companion-pro --field=version
wp plugin list | grep -i blocksy

Search for suspicious files

find wp-content/uploads -type f \( -name '*.php' -o -name '*.phtml' -o -name '*.phar' -o -name '*.*.php' \) -print
grep -Rni "save_attachments\|Advanced Reviews\|Custom Fonts" wp-content/plugins/blocksy-companion-pro

Verify the patch

wp plugin update blocksy-companion-pro
wp plugin get blocksy-companion-pro --field=version
test "$(wp plugin get blocksy-companion-pro --field=version)" \>= "2.1.47" && echo "Patched"

Dependency / inventory checks

wp plugin list --status=active
grep -Rni "blocksy-companion-pro" /var/www /srv 2>/dev/null

Web server execution test after hardening: upload should never execute from wp-content/uploads. If a test PHP file in uploads returns code execution, your server is still unsafe.

Risk and Impact

This vulnerability can give an attacker full remote code execution without authentication. In practice, that means they may be able to upload a web shell, read and modify site data, steal admin sessions, inject malware, or pivot into the rest of your hosting environment.

For small teams, the blast radius can include the WordPress database, customer data, email integrations, backups, and any secrets stored on the same server. If the site is shared hosting or part of a larger container cluster, a successful exploit can become a foothold for broader compromise.

Keep reading