Unauthenticated SQL Injection in Blocksy Companion Pro by WordPress
CVE-2026-39596

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2026

What is CVE-2026-39596?

An unauthenticated SQL Injection vulnerability exists in Blocksy Companion Pro versions prior to 2.1.29. This flaw allows an attacker to execute arbitrary SQL queries through the application's input fields, potentially leading to unauthorized access to sensitive data and disruption of service. It is crucial for users of the affected versions to update their plugins to mitigate the risks associated with this vulnerability.

Affected Version(s)

Blocksy Companion Pro < 2.1.29

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ba Khanh | Patchstack Bug Bounty Program
.