Unauthenticated Broken Access Control in Blocksy Companion Plugin
CVE-2026-97247
6.5MEDIUM
What is CVE-2026-97247?
The Blocksy Companion plugin for WordPress has a vulnerability that allows unauthenticated users to exploit broken access control mechanisms. This flaw may permit unauthorized actions within the app, potentially leading to data exposure or manipulation. Affected versions are 2.1.55 and earlier, highlighting the need for website administrators to promptly update their plugins to ensure security.
Affected Version(s)
Blocksy Companion <= 2.1.55