CVE-2026-40783
Deferred Deferred - Pending Action
Contributor RCE in Blocksy Companion Pro <= 2.1.37

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Patchstack

Description
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
blocksy companion_pro to 2.1.37 (inc)
patchstack blocksy_companion_pro to 2.1.37 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The WordPress Blocksy Companion Pro Plugin, specifically versions 2.1.37 and earlier, contains a Remote Code Execution (RCE) vulnerability. This flaw allows an attacker with contributor, developer, or creative privileges to execute arbitrary commands on the affected site.

This means the attacker can potentially gain backdoor access and full control over the website. The vulnerability is classified under the OWASP Top 10 category A3: Injection.

Impact Analysis

This vulnerability can have severe impacts as it allows attackers to execute arbitrary commands remotely on your website.

  • Attackers can gain backdoor access to your site.
  • Full control over the affected website can be obtained by the attacker.
  • It poses a high risk due to its high CVSS score of 9.9, indicating critical severity.
  • The vulnerability is likely to be exploited in mass campaigns targeting many websites.
Mitigation Strategies

Users are strongly advised to update the WordPress Blocksy Companion Pro Plugin to version 2.1.38 or later immediately to patch the Remote Code Execution vulnerability.

Until the update is applied, Patchstack has provided a mitigation rule to block attacks targeting this vulnerability.

Compliance Impact

The vulnerability allows remote code execution, enabling attackers to gain backdoor access and full control over affected sites. Such unauthorized access and control can lead to data breaches, potentially exposing sensitive personal or health information.

This exposure could result in non-compliance with regulations like GDPR and HIPAA, which mandate strict protections for personal and health data. Organizations using vulnerable versions of the Blocksy Companion Pro plugin risk violating these standards if the flaw is exploited.

Therefore, timely patching to version 2.1.38 or later is critical to maintain compliance and protect sensitive data from compromise.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40783. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart