CVE-2025-12846
Blocksy Companion
Minimum safe version
2.1.20
Update to 2.1.20 or later to address 15 fixable vulnerabilities
CVE-2025-12475
Blocksy Companion <= 2.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress Blocksy Companion Plugin <= 2.1.10 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-35633
WordPress Blocksy Companion Plugin <= 2.0.45 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-31932
CVE-2024-2392
WordPress Blocksy Companion Plugin <= 1.8.46 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-1911
CVE-2023-23898
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Blocksy Companion plugin < 1.8.20 - Sensitive Information Disclosure vulnerability
WordPress Blocksy Companion plugin < 1.8.20 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability