Blocksy Companion <= 2.1.58 - Authenticated (Contributor+) Sensitive Information Exposure via blocksy_posts Shortcode

Medium 4.3 CWE-200Fixed in 2.1.59
ID
WPSEC-2026-0686
Plugin
Blocksy Companion (blocksy-companion)
Affected
all versions before 2.1.59
Remediation
Update to 2.1.59 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-10
Attack surface
Blocksy Companion on WPSec AttackSurface
Fix released
Published

Description

The Blocksy Companion plugin for WordPress is vulnerable to Sensitive Information Exposure via the blocksy_posts shortcode and posts block in all versions up to, and including, 2.1.58. This is due to the plugin accepting arbitrary post types, including non-viewable ones, and allowing filtering by protected meta keys and values supplied in shortcode attributes. This makes it possible for authenticated attackers with Contributor-level access and above to list content from non-public post types and infer protected post meta values.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0