Security Warning: Critical vulnerabilities inWordPressplugins (CVE-2026-58480, CVE-2026-14245, CVE-2026-15158)
Discover how recent vulnerabilities inWordPressplugins can jeopardize your site’s security and find out how to prevent attacks Introduction In recent days, there have been...
Introducere
In recent days, three critical vulnerabilities have been published in theWordPressplugins, which can jeopardize the security of websites that use them. These vulnerabilities, identified with CVE-2026-58480, CVE-2026-14245 and CVE-2026-15158, can be exploited by attackers to gain unauthorized access to sites and execute arbitrary codes. In this article, we will present details about these vulnerabilities and provide recommendations for preventing attacks.
CVE-2026-58480: Vulnerability of arbitrary file uploading in the Blocksy Companion Pro plugin
The CVE-2026-58480 vulnerability affects the Blocksy Companion Pro plugin forWordPressand allows attackers to upload arbitrary files to the site, including executable files. This is due to a vulnerability in the save_attachments function, which allows attackers to bypass file extension validation and upload files with double extensions, such as shell.woff2.php. This vulnerability can be exploited to obtain unauthorized access to the site and execute arbitrary codes.
To prevent attacks that exploit this vulnerability, it is recommended to update the Blocksy Companion Pro plugin to version 2.1.47 or later. It is also recommended to regularly check the files uploaded to the site and to use a security system that detects and prevents the upload of malicious files.
CVE-2026-14245: Vulnerability bypassing authentication in miniOrange OTP Login plugin
The CVE-2026-14245 vulnerability affects the miniOrange OTP Login plugin forWordPressand allows attackers to bypass authentication and gain unauthorized access to administrator accounts. This is due to a vulnerability in the um_reset_password_process_hook function, which does not correctly check whether the OTP validation steps have been completed and relies exclusively on a public form token that can be controlled by attackers.
To prevent attacks that exploit this vulnerability, it is recommended to update the miniOrange OTP Login plugin to version 5.5.2 or later. It is also recommended to use a security system that detects and prevents authentication bypass attacks.
CVE-2026-15158: Vulnerability of arbitrary file uploading into the Blocksy Companion plugin
The CVE-2026-15158 vulnerability affects the Blocksy Companion plugin forWordPressand allows attackers to upload arbitrary files to the site, including executable files. This is due to a vulnerability in the save_attachments function, which allows attackers to bypass file extension validation and upload files with double extensions, such as shell.woff2.php.
To prevent attacks that exploit this vulnerability, it is recommended to update the Blocksy Companion plugin to version 2.1.47 or later. It is also recommended to regularly check the files uploaded to the site and to use a security system that detects and prevents the upload of malicious files.
Practical implications for readers
These vulnerabilities can have significant practical implications for readers using the affected plugins. Attackers can exploit these vulnerabilities to gain unauthorized access to sites, execute arbitrary codes and steal confidential information. These vulnerabilities can also be used to distribute malware and compromise site security.
To prevent attacks, it is essential to update the plugins to the newer versions and use a security system that detects and prevents attacks. It is also recommended to regularly check the files uploaded to the site and use a backup system to ensure data recovery in the event of an attack.
What can you do today
-
Updates plugins to new versions to prevent attacks
-
Regularly check the files uploaded to the site to detect and prevent the upload of malicious files
-
Use a security system to detect and prevent attacks
-
Use a backup system to ensure data recovery in the event of an attack
Therefore, it is essential to take immediate action to prevent attacks that exploit these vulnerabilities. If you need help with updating your plugins or implementing a security system, please contact us at https://zebrabyte.ro/contact.
Monitoring and protecting websites from cyber attacks are essential to prevent financial and image losses. AtZebrabytewe offer site monitoring and protection services including plugin updating and security systems implementation. Contact us today to find out how we can help you protect your site.
ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.