Skip to main content
Loading…
    CVE-2025-12846 — The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2.1.19. This is due to insufficient file type validation detecting — CVE Database · The Intelligence Room