Critical Unauthenticated RCE in Blocksy Companion Pro: Immediate Mitigation Required for Enterprise WordPress Deployments
Overview
CVE-2026-57624 exposes WordPress sites using Blocksy Companion Pro to unauthenticated remote code execution, enabling attackers to compromise servers without credentials. With a CVSS score of 10.0, this vulnerability presents an imminent threat requiring urgent attention.
Technical Analysis
The vulnerability arises from improper input validation in a public-facing endpoint of Blocksy Companion Pro versions up to 2.1.46. Attackers can exploit this by injecting malicious PHP code via a tailored HTTP request, which is then executed with server privileges. The absence of authentication checks allows threat actors to bypass all standard WordPress security mechanisms. This technical flaw can be triggered through simple GET requests, making exploitation exceptionally straightforward.
Enterprise & DIB Impact
DIB and enterprise environments often rely on WordPress for critical internal and external systems. Successful exploitation here could lead to full server compromise, data exfiltration, or ransomware deployment. Given the unauthenticated nature, attackers need only locate exposed instances to initiate attacks, which are likely automated in volume.
Recommended Actions
- Upgrade to Blocksy Companion Pro version 2.1.47 or later
- apply recommended patches from the vendor immediately
- configure WAFs to block suspicious requests to the plugin endpoint
- and disable Blocksy Companion Pro on non-production environments until patches are verified
Need Help Assessing Your Exposure?
Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.
Schedule a ConsultationFull security advisory on 247alerts.net →