CVE-2026-15158 is an arbitrary file upload vulnerability affecting the Blocksy Companion plugin ecosystem for WordPress in versions up to and including 2.1.46, specifically in exploitable premium configurations of blocksy-companion-pro. The flaw is in the save_attachments function and stems from the Custom Fonts extension registering a wp_check_filetype_and_ext filter that validates filenames incorrectly. Instead of verifying that the final extension is an allowed font type, the code uses substring matching and approves any filename containing .woff2 or .ttf anywhere in the name. As a result, double-extension files can bypass validation and be treated as permitted font uploads. Under the affected configuration, unauthenticated attackers can upload files that may be interpreted as executable by the server, creating a path to remote code execution. The free blocksy-companion plugin does not contain the vulnerable code paths.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit for CVE-2026-58480 / CVE-2026-15158 affecting Blocksy Companion Pro before 2.1.47 on WordPress. It contains two files: a README describing the vulnerability, prerequisites, and usage, and a single executable script, exploit.py, which performs fingerprinting, upload attempts, and shell discovery. The exploit targets an unauthenticated file upload in the Advanced Reviews functionality, relying on a weak Custom Fonts filename validation check that accepts filenames containing .woff2 or .ttf anywhere in the name. The script abuses this by generating or accepting a double-extension filename such as randomname.woff2.php and uploading a PHP webshell through the vulnerable AJAX handler using the multipart parameter blc-review-images[]. Primary capabilities implemented in exploit.py: - Fingerprints WordPress/Blocksy deployments by requesting /wp-content/themes/blocksy/style.css and /wp-content/plugins/blocksy-companion/readme.txt. - Parses detected version strings and flags versions below 2.1.47 as vulnerable. - Tries multiple possible AJAX action names associated with the save_attachments handler to improve reliability across deployments. - Uploads a hardcoded PHP command shell payload. - Searches likely upload directories under wp-content/uploads and related paths for the uploaded shell. - Supports single-target checking/exploitation and bulk target processing per the README examples. The payload is a basic PHP webshell that executes arbitrary system commands passed via the cmd request parameter using system(). This makes the exploit operational rather than a mere proof of concept. It is not part of a larger exploitation framework. Notable fingerprintable artifacts include the WordPress AJAX endpoint /wp-admin/admin-ajax.php, the upload parameter blc-review-images[], multiple candidate AJAX action names, and several likely shell locations under /wp-content/uploads/. The exploit assumes the target permits execution of uploaded PHP files from the uploads path; if PHP execution is disabled there, upload may succeed without yielding RCE.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.