Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Blocksy — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Blocksy, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with the Blocksy product, developed by the Vendor. It specifically covers weaknesses classified under general software vulnerability categories, providing a comprehensive overview of security issues linked to this popular WordPress theme. The aggregation collects data on known exploits, configuration flaws, and coding errors ranging from early releases to the most recent updates, ensuring a historical perspective on the product's security posture. Here, you can track a vendor's advisories as they emerge, allowing you to stay informed about patch releases and mitigation strategies in real-time. Furthermore, the page helps you understand a weakness class by detailing how specific vulnerabilities manifest within the Blocksy ecosystem, offering technical insights into the root causes and potential impacts. Users can also look up a product's vulnerability history to assess long-term security trends, compare fixes across versions, and make informed decisions regarding updates or alternative solutions. This resource serves as a centralized reference for developers, administrators, and security researchers seeking to evaluate the risk profile of Blocksy. By examining the collected data, stakeholders can identify recurring patterns, prioritize remediation efforts, and enhance the overall resilience of their WordPress installations against known threats.

Vendor: creativethemeshq

CVE IDTitleCVSSSeverityPublished
CVE-2026-8365 Blocksy <= 2.1.41 - Authenticated (Contributor+) PHP Object Injection via Deserialization of Untrusted Data via 'blocksy_meta' REST API Field CWE-502 8.8 High2026-06-09
CVE-2026-2583 Blocksy <= 2.1.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via `blocksy_meta` Fields CWE-79 6.4 Medium2026-03-02
CVE-2025-55713 WordPress Blocksy Theme <= 2.1.6 - Cross Site Scripting (XSS) Vulnerability CWE-79 5.9 Medium2025-08-14
CVE-2025-47465 WordPress Blocksy theme <= 2.0.97 - Broken Access Control Vulnerability CWE-862 4.9 Medium2025-05-07
CVE-2024-37469 WordPress Blocksy theme <= 1.9.5 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 5.4 Medium2025-01-02
CVE-2024-11420 Blocksy <= 2.0.77 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-12-05
CVE-2024-5439 Blocksy <= 2.0.50 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-20 6.4 Medium2024-06-05
CVE-2024-4943 Blocksy <= 2.0.46 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-05-21
CVE-2024-4158 Blocksy <= 2.0.42 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-05-09
CVE-2024-3747 Blocksy <= 2.0.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via About Me block CWE-20 6.4 Medium2024-05-02
CVE-2024-32961 WordPress Blocksy theme <= 2.0.33 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-04-25
CVE-2024-31382 WordPress Blocksy theme <= 2.0.22 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium2024-04-15
CVE-2024-1767 Blocksy <= 2.0.26 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-03-09
CVE-2024-24871 WordPress Blocksy theme <= 2.0.19 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-02-08

All 14 known CVE vulnerabilities affecting Blocksy with full Chinese analysis, references, and POCs where available.