WP Vulnerability WatchVulnerability data as of September 7, 2026

Vulnerability alerts / September 1, 2026

Vulnerability in Blocksy Companion — CVE-2026-18488

MediumSeverity
CVSS 6.4
0.3%Estimated exploit probability
EPSS
300,000+ sitesInstalls
2.1.52Fixed in

What to do now

Update Blocksy Companion to 2.1.52 or later.

Affected versions

  • Everything up to and including 2.1.51

Affected: Blocksy Companion (plugin, blocksy-companion)

Check: The plugin on wordpress.org / Our record for Blocksy Companion

What the vulnerability is

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions up to, and including, 2.1.51 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

This description is reproduced verbatim from the public vulnerability record.

Sources

See other alerts