CVE-2026-58480
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-58480 is indexed in Exploit-DB and GitHub PoC. Expect opportunistic scanning and exploitation attempts — prioritize remediation even though it is not (yet) in the CISA KEV catalog.
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.
⚡ Watch CVE-2026-58480
Get an email if CVE-2026-58480 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Moderate exploitation risk3.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 88% of all EPSS-scored CVEs.
Exploit availability
Public exploit or proof-of-concept code for CVE-2026-58480 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.
- Exploit-DBA public exploit is published in the Exploit-DB archive.look it up ↗
- GitHub PoCPublic proof-of-concept repositories on GitHub reference this CVE.look it up ↗
Advisory coverage (1)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-58480)