Creativethemes develops WordPress themes and plugins, primarily the Blocksy theme and its companion plugin, which serve a modestly represented but prominent footprint across WordPress sites. The vendor's disclosures cluster around web-application input-handling and authorization weaknesses, including cross-site scripting, cross-site request forgery, input-validation flaws, and server-side request forgery, reflecting the attack surface of widely deployed client-side and server-side WordPress components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Creativethemes over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-58480CRITICAL Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassi | Jul 8, 2026 | 9.8 | 42 | NO | NO |
CVE-2024-31382HIGH Cross-Site Request Forgery (CSRF) vulnerability in creativethemeshq Blocksy blocksy.This issue affects Blocksy: from n/a through <= 2.0.22. | Apr 15, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-31932HIGH Cross-Site Request Forgery (CSRF) vulnerability in CreativeThemes Blocksy Companion.This issue affects Blocksy Companion: from n/a through 2.0.28. | Apr 11, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-37469HIGH Cross-Site Request Forgery (CSRF) vulnerability in creativethemeshq Blocksy blocksy allows Cross Site Request Forgery.This issue affects Blocksy: from n/a through <= 2.0.22. | Jan 2, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-2392MEDIUM The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 due to insuf | Mar 22, 2024 | 6.4 | 19 | NO | NO |
CVE-2024-24871MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq Blocksy blocksy.This issue affects Blocksy: from n/a through | Feb 8, 2024 | 5.4 | 19 | NO | NO |
CVE-2023-23898MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions. | Apr 6, 2023 | 5.4 | 19 | NO | NO |
CVE-2024-5439MEDIUM The Blocksy theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the custom_url parameter in all versions up to, and including, 2.0.50 due to insufficient input | Jun 5, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-1767MEDIUM The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.0.26 due to insufficient input sanitiza | Mar 9, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-1911MEDIUM The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated user | May 2, 2023 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Creativethemes.
Media articles that mention a CVE ID that affects a product developed by Creativethemes — matched by CVE ID, not by vendor name.