Blocksy Security & Risk Analysis

wordpress.org/themes/blocksy

Blocksy is a fast, modern WordPress theme with advanced WooCommerce support and full compatibility with the block editor.

v2.1.35 300K active installs creativethemeshq Updated Mar 12, 2026
95
A · Safe
CVEs total12
Unpatched0
Last CVEMar 2, 2026

Is Blocksy Safe to Use in 2026?

Generally Safe

Score 95/100

Blocksy has a strong security track record. Known vulnerabilities have been patched promptly.

12 known CVEsLast CVE: Mar 2, 2026Updated 22d ago

Blocksy Security Vulnerabilities 12

CVEs by Year

9 CVEs in 2024
2024
2 CVEs in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
11
Low
1

12 total CVEs

CVE-2026-2583medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Blocksy <= 2.1.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via `blocksy_meta` Fields

Mar 2, 2026 Patched in 2.1.31 (1d)
CVE-2025-55713medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Blocksy <= 2.1.6 - Authenticated (Shop manager+) Stored Cross-Site Scripting

Aug 14, 2025 Patched in 2.1.7 (5d)
CVE-2025-47465low · 2.7Missing Authorization

Blocksy <= 2.0.97 - Missing Authorization

May 7, 2025 Patched in 2.0.98 (8d)
CVE-2024-11420medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Blocksy <= 2.0.77 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 4, 2024 Patched in 2.0.78 (1d)
CVE-2024-5439medium · 6.4Improper Input Validation

Blocksy <= 2.0.50 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jun 4, 2024 Patched in 2.0.51 (1d)
CVE-2024-4943medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Blocksy <= 2.0.46 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 20, 2024 Patched in 2.0.47 (1d)
CVE-2024-4158medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Blocksy <= 2.0.42 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 3, 2024 Patched in 2.0.43 (7d)
CVE-2024-3747medium · 6.4Improper Input Validation

Blocksy <= 2.0.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via About Me block

Apr 24, 2024 Patched in 2.0.40 (9d)
CVE-2024-32961medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Blocksy <= 2.0.33 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 23, 2024 Patched in 2.0.34 (7d)
CVE-2024-31382medium · 4.3Cross-Site Request Forgery (CSRF)

Blocksy <= 2.0.22 - Cross-Site Request Forgery to Notice Dismissal

Apr 10, 2024 Patched in 2.0.23 (91d)
CVE-2024-1767medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Blocksy <= 2.0.26 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 8, 2024 Patched in 2.0.27 (1d)
CVE-2024-24871medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Blocksy <= 2.0.19 - Authenticated (Editor+) Stored Cross-Site Scripting

Feb 5, 2024 Patched in 2.0.20 (4d)

Developer Profile

Creative Themes

2 plugins · 600K total installs

84
trust score
Avg Security Score
94/100
Avg Patch Time
50 days
View full developer profile