Blocksy Companion

Blocksy Companion Vulnerability – Authenticated (Admin+) Server-Side Request Forgery – CVE-2024-35633 | WordPress Plugin Vulnerability Report

By Your WP Guy / May 30, 2024

Plugin Name: Blocksy Companion Key Information: Software Type: Plugin Software Slug: blocksy-companion Software Status: Active Software Author: creativethemeshq Software Downloads: 7,853,860 Active Installs: 200,000 Last Updated: June 11, 2024 Patched Versions: 2.0.43 Affected Versions: <= 2.0.42 Vulnerability Details: Name: Blocksy Companion <= 2.0.42 Type: Authenticated (Admin+) Server-Side Request Forgery CVE: CVE-2024-35633 CVSS Score: 5.5 Publicly…

Read More

Blocksy Companion Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Uploads – CVE-2024-4487 | WordPress Plugin Vulnerability Report

By Your WP Guy / May 10, 2024

Plugin Name: Blocksy Companion Key Information: Software Type: Plugin Software Slug: blocksy-companion Software Status: Active Software Author: creativethemeshq Software Downloads: 7,639,072 Active Installs: 200,000 Last Updated: May 10, 2024 Patched Versions: 2.0.46 Affected Versions: <= 2.0.45 Vulnerability Details: Name: Blocksy Companion <= 2.0.45 – Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Uploads Type: Improper Neutralization…

Read More

Blocksy Companion Vulnerability – Cross-Site Request Forgery – CVE-2024-31932 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Apr 10, 2024

Plugin Name: Blocksy Companion Key Information: Software Type: Plugin Software Slug: blocksy-companion Software Status: Active Software Author: creativethemeshq Software Downloads: 7,114,824 Active Installs: 200,000 Last Updated: April 24, 2024 Patched Versions: 2.0.29 Affected Versions: <= 2.0.28 Vulnerability Details: Name: Blocksy Companion <= 2.0.28 Title: Cross-Site Request Forgery Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE: CVE-2024-31932 CVSS Score: 5.3 Publicly…

Read More