CVE-2026-57624: WordPress Blocksy Companion Pro plugin <= 2.1.46 - Remote Code Execution (RCE) vulnerability
Published Jul 2, 2026
·Updated
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
Affected Software
1 affected component
WordPress Blocksy Companion Pro plugin<=2.1.46
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Blocksy Companion Proto a version that resolves this vulnerability.Fixed in 2.1.47
Event History
Jul 2, 2026
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57624?
CVE-2026-57624 is classified as critical with a severity score of 10.
2
How do I fix CVE-2026-57624?
To mitigate CVE-2026-57624, upgrade the Blocksy Companion Pro plugin to version 2.1.47 or later.
3
What type of vulnerability is CVE-2026-57624?
CVE-2026-57624 is a remote code execution (RCE) vulnerability.
4
What software is affected by CVE-2026-57624?
CVE-2026-57624 affects versions of the WordPress Blocksy Companion Pro plugin up to and including 2.1.46.
5
Is authentication required to exploit CVE-2026-57624?
No, CVE-2026-57624 can be exploited without authentication.