PT-2025-46324 · WordPress · Blocksy Companion

Angus Girvan

·

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2025-12846

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Blocksy Companion plugin for WordPress versions up to and including 2.1.19
Description The Blocksy Companion plugin for WordPress is susceptible to authenticated arbitrary file upload due to insufficient file type validation. Specifically, the plugin fails to properly detect SVG files, allowing files with double extensions to bypass sanitization. This enables authenticated attackers with author-level access or higher to upload arbitrary files to the affected server, potentially leading to remote code execution. The file parameter in the upload process is vulnerable.
Recommendations Update the Blocksy Companion plugin to a version later than 2.1.19.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-12846

Affected Products

Blocksy Companion