Blocksy

Blocksy has 14 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 14 are fixed as of September 2026. Their average CVSS score is 5.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2024 was the busiest year with 10 disclosures.

The most common weakness is Cross-Site Scripting, behind 8 of the records (57%). Other recurring categories include Cross-Site Request Forgery (CSRF), Improper Input Validation.

Every one of the 14 issues recorded for Blocksy has a vendor fix available, so running the current release closes all known holes.

7 independent researchers contributed these findings, most of them (5) reported by Ngô Thiên An (ancorn_). Blocksy is installed on roughly 300,000 WordPress sites, so each unpatched flaw has a wide blast radius.

01234567891010.05.2019Today05.02.20244.4Blocksy <= 2.0.19 - Authenticated (Editor+) Stored Cross-Site Scripting CVSS 4.4 · 05.02.202408.03.20246.4Blocksy <= 2.0.26 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 08.03.202410.04.20244.3Blocksy <= 2.0.22 - Cross-Site Request Forgery to Notice Dismissal CVSS 4.3 · 10.04.202423.04.20246.4Blocksy <= 2.0.33 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 23.04.202424.04.20246.4Blocksy <= 2.0.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via About Me block CVSS 6.4 · 24.04.202403.05.20246.4Blocksy <= 2.0.42 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 03.05.202420.05.20246.4Blocksy <= 2.0.46 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 20.05.202404.06.20246.4Blocksy <= 2.0.50 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 04.06.202401.07.20244.3Blocksy <= 2.0.22 - Cross-Site Request Forgery CVSS 4.3 · 01.07.202404.12.20246.4Blocksy <= 2.0.77 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 04.12.202407.05.20252.7Blocksy <= 2.0.97 - Missing Authorization CVSS 2.7 · 07.05.202514.08.20255.5Blocksy <= 2.1.6 - Authenticated (Shop manager+) Stored Cross-Site Scripting CVSS 5.5 · 14.08.202502.03.20266.4Blocksy <= 2.1.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via `blocksy_meta` Fields CVSS 6.4 · 02.03.202608.06.20268.8Blocksy <= 2.1.41 - Authenticated (Contributor+) PHP Object Injection via Deserialization of Untrusted Data via 'blocksy_meta' REST API Field CVSS 8.8 · 08.06.2026

Strategic Overview

Avg CVSSMedium
5.8/ 10
Patch Coverage100%
Open

0

Fixed

14

Get automatic notifications for all Blocksy vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2026-8365

Blocksy <= 2.1.41 - Authenticated (Contributor+) PHP Object Injection via Deserialization of Untrusted Data via 'blocksy_meta' REST API Field

Read the full analysis

Vulnerability Records

14 records
2026-06-08 20:11CVE-2026-8365
8.8
High
Quốc Huy (jtwings)Yes
2026-03-02 09:26CVE-2026-2583
6.4
Medium
Quốc Huy (jtwings)Yes
2025-08-14 00:00CVE-2025-55713
5.5
Medium
SavPhill (Savphill)Yes
2025-05-07 00:00CVE-2025-47465
2.7
Low
SavPhill (Savphill)Yes
2024-12-04 00:00CVE-2024-11420
6.4
Medium
zer0gh0stYes
2024-07-01 00:00CVE-2024-37469
4.3
Medium
RE-ALTERYes
2024-06-04 19:06CVE-2024-5439
6.4
Medium
Ngô Thiên An (ancorn_)Yes
2024-05-20 14:17CVE-2024-4943
6.4
Medium
Ngô Thiên An (ancorn_)Yes
2024-05-03 00:00CVE-2024-4158
6.4
Medium
Ngô Thiên An (ancorn_)Yes
2024-04-24 00:00CVE-2024-3747
6.4
Medium
Ngô Thiên An (ancorn_)Yes
Showing 1–10 of 14 reports
Blocksy screenshot
Latestv2.1.57
5.0(872)
100/100
Last Updated
2026-09-11 (2d ago)
Active Installs
300,000+
Downloads
7,790,896
Requires WP
6.7+
Requires PHP
7.0+
Created
2019-05-10 (7y ago)

Blocksy is a fast, modern WordPress theme with advanced WooCommerce support and full compatibility with the block editor.

Tags
BlogE commerceOne columnCustom logoCustom menuGrid layoutTwo columnsWide blocksBlock editor stylesFour columnsLeft sidebarCustom colorsRight sidebarTheme optionsThree columnsBlock editor patternsFooter widgetsFeatured imagesThreaded commentsTranslation readyAccessibility readyFull width template

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C