Unauthenticated SQL Injection in Blocksy Companion Pro by WordPress
CVE-2026-39596
9.3CRITICAL
What is CVE-2026-39596?
An unauthenticated SQL Injection vulnerability exists in Blocksy Companion Pro versions prior to 2.1.29. This flaw allows an attacker to execute arbitrary SQL queries through the application's input fields, potentially leading to unauthorized access to sensitive data and disruption of service. It is crucial for users of the affected versions to update their plugins to mitigate the risks associated with this vulnerability.
Affected Version(s)
Blocksy Companion Pro < 2.1.29