CVE-2026-107645
Received Received - Intake

Privilege Escalation in Blocksy Companion WordPress Plugin

Vulnerability report for CVE-2026-107645, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58 This is due to the implement_user_registration() AJAX handler explicitly disabling Dokan's vendor-registration nonce check (via add_filter('dokan_register_nonce_check', '__return_false')) and then trusting an attacker-supplied $_POST['role'] value when invoking wc_create_new_customer() and wc_set_customer_auth_cookie(). This makes it possible for unauthenticated attackers to elevate their privileges to a Dokan 'seller' (vendor) account β€” including sites where the Dokan vendor signup is explicitly turned off β€” and to be auto-authenticated into that account, which grants publishing capabilities beyond those of a normal customer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
creativethemeshq Blocksy Companion 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Blocksy Companion WordPress plugin up to version 2.1.58 has a privilege escalation flaw. It disables a security check for vendor registration and allows attackers to set their own user role via a POST request. This lets unauthenticated users create accounts with elevated 'seller' privileges and be automatically logged in.

Detection Guidance

Check for unauthorized user registrations with the 'seller' or 'vendor' role in WordPress. Review logs for AJAX calls to Blocksy Companion's implement_user_registration() handler. Look for unexpected wc_create_new_customer() or wc_set_customer_auth_cookie() invocations.

Impact Analysis

Unauthenticated attackers could gain control of a WordPress site by creating a privileged account. This could allow them to publish content, modify site settings, or install malicious plugins. Even if vendor registration is disabled, the flaw still works.

Mitigation Strategies

Update the Blocksy Companion plugin to the latest version. Disable the plugin if not needed. Implement WordPress hardening measures like disabling user registration or restricting registration to specific roles. Monitor for suspicious user creation events.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107645. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart