← WordPress Vulnerabilities
WordPress security by component

Blocksy

Blocksy is a fast, modern WordPress theme with advanced WooCommerce support and full compatibility with the block editor.

Theme slug: blocksy · Description source: WordPress.org

CVE-2026-8365: Blocksy: Code execution

Blocksy is affected by code execution. Exploitation requires at least contributor-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 2.1.41.

PublishedJun 09, 2026
Known safe version> 2.1.41
Safe version
Jun 09, 2026 CVE-2026-8365
Blocksy: Code execution
Blocksy is affected by code execution. Exploitation requires at least contributor-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 2.1.41.
> 2.1.41
CVE8.8
NVDPending
Mar 02, 2026 CVE-2026-2583
Blocksy: Cross-site scripting
Blocksy is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Aug 14, 2025 CVE-2025-55713
Blocksy: Cross-site scripting
Blocksy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
May 07, 2025 CVE-2025-47465
Blocksy: A security weakness
Blocksy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.9
NVDPending
Jan 02, 2025 CVE-2024-37469
Blocksy: Cross-site request forgery
Blocksy is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Dec 05, 2024 CVE-2024-11420
Blocksy: Cross-site scripting
Blocksy is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 05, 2024 CVE-2024-5439
Blocksy: Cross-site scripting
Blocksy is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 21, 2024 CVE-2024-4943
Blocksy: Cross-site scripting
Blocksy is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 14, 2024 CVE-2024-4158
Blocksy: Cross-site scripting
Blocksy is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-3747
Blocksy: Cross-site scripting
Blocksy is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 25, 2024 CVE-2024-32961
Blocksy: Cross-site scripting
Blocksy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Apr 15, 2024 CVE-2024-31382
Blocksy: Cross-site request forgery
Blocksy is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Mar 09, 2024 CVE-2024-1767
Blocksy: Cross-site scripting
Blocksy is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 08, 2024 CVE-2024-24871
Blocksy: Cross-site scripting
Blocksy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4