A critical remote code execution (RCE) vulnerability has been identified in Blocksy Companion Pro versions 2.1.37 and earlier. This vulnerability allows a remote attacker to execute arbitrary code on the target system, potentially leading to complete system compromise. The vulnerability affects users of the Blocksy Companion Pro plugin on WordPress platforms. Given the CVSS score of 9.9, this is classified as a critical severity issue. Attackers could exploit this vulnerability without authentication, making it particularly dangerous. Organizations and individuals using affected versions of the plugin are strongly advised to update to a patched version immediately. Failure to apply the necessary patches could result in unauthorized access, data breaches, or other malicious activities. It is recommended to monitor for any signs of unauthorized access or unusual system behavior. Users should consult the official plugin repository for the latest security updates and ensure all software components are kept up to date. This advisory underscores the importance of timely patch management to mitigate such high-severity vulnerabilities.
CRITICAL
CVSS 9.9
CVE-2026-40783
2026-08-22
Critical RCE Vulnerability in Blocksy Companion Pro (CVE-2026-40783)
A critical remote code execution vulnerability exists in Blocksy Companion Pro versions 2.1.37 and below, affecting WordPress platforms. This allows attackers to execute arbitrary code remotely, posing a severe security risk.