Blocksy Companion

Blocksy Companion is a plugin that enhances the Blocksy theme, but only if it is installed and active. The minimum requirements for the plugin include WordPress 5.0 or greater and PHP version 7.0 or greater.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in Blocksy Companion 2.0.42

    Fixed

    The Blocksy Companion plugin for WordPress has a security issue that allows hackers to send requests from the website to other places on the internet. This can be done by someone who has high-level a...

    Read More
  • Input validation vulnerability in Blocksy Companion 2.0.45

    Fixed

    The Blocksy Companion plugin for WordPress is at risk of being hacked through a type of attack called Stored Cross-Site Scripting. This can happen when someone uploads a certain type of file, called ...

    Read More
  • Input validation vulnerability in Blocksy Companion 2.0.28

    Fixed

    The Blocksy Companion plugin for WordPress has a security issue in versions up to 2.0.28. This is because it does not properly check for a special code to verify the identity of the user. As a result...

    Read More
  • Input validation vulnerability in Blocksy Companion 2.0.31

    Fixed

    The Blocksy Companion plugin for WordPress can be hacked through the plugin's Newsletter widget. This is because the plugin does not properly protect against harmful code that users may input. This a...

    Read More
  • Input validation vulnerability in Freemius SDK 2.5.9 (1072 components affected)

    Fixed

    The Freemius SDK for WordPress is vulnerable to an attack known as Reflected Cross-Site Scripting. This attack is possible because of insufficient security measures in versions of the Freemius SDK up ...

    Read More
  • Access violation vulnerability in Blocksy Companion 1.8.81

    Fixed

    The Blocksy Companion plugin for WordPress is not secure in versions up to 1.8.81. Someone with access to the plugin (such as an attacker with subscriber-level permissions or higher) can find sensitiv...

    Read More
  • Input validation vulnerability in Blocksy Companion 1.8.68

    Fixed

    The Blocksy Companion plugin for WordPress is not secure in versions up to 1.8.67 and can be exploited by attackers who have contributor-level permissions or higher. This vulnerability allows attacker...

    Read More
  • Access violation vulnerability in Freemius SDK (620 components affected)

    Fixed

    Freemius, a software development kit used by hundreds of WordPress plugin and theme developers, had a security vulnerability in its older versions (up to and including 2.4.2). This vulnerability could...

    Read More