Skip to main content
Back to Blog
13 July 2026, byZebrabyte Breaches and incidents

Security Warning: Critical vulnerabilities inWordPressplugins (CVE-2026-58480, CVE-2026-14245, CVE-2026-15158)

Security Warning: Critical vulnerabilities inWordPressplugins (CVE-2026-58480, CVE-2026-14245, CVE-2026-15158)

Discover how recent vulnerabilities inWordPressplugins can jeopardize your site’s security and find out how to prevent attacks Introduction In recent days, there have been...

Introducere

In recent days, three critical vulnerabilities have been published in theWordPressplugins, which can jeopardize the security of websites that use them. These vulnerabilities, identified with CVE-2026-58480, CVE-2026-14245 and CVE-2026-15158, can be exploited by attackers to gain unauthorized access to sites and execute arbitrary codes. In this article, we will present details about these vulnerabilities and provide recommendations for preventing attacks.

CVE-2026-58480: Vulnerability of arbitrary file uploading in the Blocksy Companion Pro plugin

The CVE-2026-58480 vulnerability affects the Blocksy Companion Pro plugin forWordPressand allows attackers to upload arbitrary files to the site, including executable files. This is due to a vulnerability in the save_attachments function, which allows attackers to bypass file extension validation and upload files with double extensions, such as shell.woff2.php. This vulnerability can be exploited to obtain unauthorized access to the site and execute arbitrary codes.

To prevent attacks that exploit this vulnerability, it is recommended to update the Blocksy Companion Pro plugin to version 2.1.47 or later. It is also recommended to regularly check the files uploaded to the site and to use a security system that detects and prevents the upload of malicious files.

CVE-2026-14245: Vulnerability bypassing authentication in miniOrange OTP Login plugin

The CVE-2026-14245 vulnerability affects the miniOrange OTP Login plugin forWordPressand allows attackers to bypass authentication and gain unauthorized access to administrator accounts. This is due to a vulnerability in the um_reset_password_process_hook function, which does not correctly check whether the OTP validation steps have been completed and relies exclusively on a public form token that can be controlled by attackers.

To prevent attacks that exploit this vulnerability, it is recommended to update the miniOrange OTP Login plugin to version 5.5.2 or later. It is also recommended to use a security system that detects and prevents authentication bypass attacks.

CVE-2026-15158: Vulnerability of arbitrary file uploading into the Blocksy Companion plugin

The CVE-2026-15158 vulnerability affects the Blocksy Companion plugin forWordPressand allows attackers to upload arbitrary files to the site, including executable files. This is due to a vulnerability in the save_attachments function, which allows attackers to bypass file extension validation and upload files with double extensions, such as shell.woff2.php.

To prevent attacks that exploit this vulnerability, it is recommended to update the Blocksy Companion plugin to version 2.1.47 or later. It is also recommended to regularly check the files uploaded to the site and to use a security system that detects and prevents the upload of malicious files.

Practical implications for readers

These vulnerabilities can have significant practical implications for readers using the affected plugins. Attackers can exploit these vulnerabilities to gain unauthorized access to sites, execute arbitrary codes and steal confidential information. These vulnerabilities can also be used to distribute malware and compromise site security.

To prevent attacks, it is essential to update the plugins to the newer versions and use a security system that detects and prevents attacks. It is also recommended to regularly check the files uploaded to the site and use a backup system to ensure data recovery in the event of an attack.

What can you do today

  • Updates plugins to new versions to prevent attacks

  • Regularly check the files uploaded to the site to detect and prevent the upload of malicious files

  • Use a security system to detect and prevent attacks

  • Use a backup system to ensure data recovery in the event of an attack

Therefore, it is essential to take immediate action to prevent attacks that exploit these vulnerabilities. If you need help with updating your plugins or implementing a security system, please contact us at https://zebrabyte.ro/contact.

Monitoring and protecting websites from cyber attacks are essential to prevent financial and image losses. AtZebrabytewe offer site monitoring and protection services including plugin updating and security systems implementation. Contact us today to find out how we can help you protect your site.


Scris de Zebrabyte

ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.

ReceiveZebraByteanalytics and guidelines on cyber security, privacy and compliance.
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert