CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-58480

criticalpublic exploitCVSS 9.8covered by 1 sourcefirst seen 2026-07-08
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-58480 is indexed in Exploit-DB and GitHub PoC. Expect opportunistic scanning and exploitation attempts — prioritize remediation even though it is not (yet) in the CISA KEV catalog.
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.

⚡ Watch CVE-2026-58480

Get an email if CVE-2026-58480 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Exploit availability

Public exploit or proof-of-concept code for CVE-2026-58480 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.

Advisory coverage (1)

External references

NVD record for CVE-2026-58480

CVE.org record

Embed the live status

CVE-2026-58480 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-58480 status](https://www.csirts.com/badge/CVE-2026-58480)](https://www.csirts.com/cve/CVE-2026-58480)