← Back to Research Blog
CRITICAL CVE-2026-57624

Critical Unauthenticated RCE in Blocksy Companion Pro: Immediate Mitigation Required for Enterprise WordPress Deployments

10.0
CRITICAL
blocksy_companion_pro, wordpress
2026-07-15

Overview

CVE-2026-57624 exposes WordPress sites using Blocksy Companion Pro to unauthenticated remote code execution, enabling attackers to compromise servers without credentials. With a CVSS score of 10.0, this vulnerability presents an imminent threat requiring urgent attention.


Technical Analysis

The vulnerability arises from improper input validation in a public-facing endpoint of Blocksy Companion Pro versions up to 2.1.46. Attackers can exploit this by injecting malicious PHP code via a tailored HTTP request, which is then executed with server privileges. The absence of authentication checks allows threat actors to bypass all standard WordPress security mechanisms. This technical flaw can be triggered through simple GET requests, making exploitation exceptionally straightforward.

Enterprise & DIB Impact

DIB and enterprise environments often rely on WordPress for critical internal and external systems. Successful exploitation here could lead to full server compromise, data exfiltration, or ransomware deployment. Given the unauthenticated nature, attackers need only locate exposed instances to initiate attacks, which are likely automated in volume.

Recommended Actions

Need Help Assessing Your Exposure?

Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.

Schedule a Consultation
Full security advisory on 247alerts.net →
Axiom Cyber Research
Axiom Cyber Research, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing elite cybersecurity consulting to the Defense Industrial Base and regulated sectors. Founded by a 20+ year veteran with deep offensive and defensive cyber expertise. Our CVE intelligence program actively tracks emerging vulnerabilities to help organizations prioritize remediation and reduce exposure windows.
Baltimore, MD  ·  axiomcyber.io  ·  247alerts.net  ·  SDVOSB  ·  NAICS 541512