Unauthenticated Privilege Escalation in Blocksy Companion Plugin for WordPress
The Blocksy Companion WordPress plugin is vulnerable to unauthenticated privilege escalation, allowing attackers to create arbitrary vendor accounts by bypassing Dokan registration security checks.
CVE search metadata
CVE search record: CVE-2026-107645. Severity: critical. CVSS: 9.1. KEV: no. Product: Blocksy Companion (<= 2.1.58). Brief: Unauthenticated Privilege Escalation in Blocksy Companion Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-blocksy-privilege-escalation/
The Blocksy Companion plugin for WordPress, in versions up to and including 2.1.58, contains a critical vulnerability (CVE-2026-107645) that enables unauthenticated privilege escalation. The vulnerability resides in the implement_user_registration() AJAX handler, which incorrectly disables the Dokan vendor-registration nonce check by executing add_filter('dokan_register_nonce_check', '__return_false').
By sending a specially crafted request to this endpoint, an unauthenticated attacker can supply an arbitrary role parameter to wc_create_new_customer() and wc_set_customer_auth_cookie(). This process ignores site-wide settings that may have disabled vendor registration, automatically creating and authenticating a user with 'seller' (vendor) privileges. This grants the attacker elevated publishing capabilities on the affected WordPress site, significantly expanding their control beyond that of a standard customer. Because this exploit operates via the public-facing AJAX handler, it is accessible to any remote, unauthenticated user, representing a high risk for sites running the vulnerable plugin configuration.
Attack Chain
- Attacker identifies a target WordPress site running the vulnerable Blocksy Companion plugin (version <= 2.1.58) with the Dokan plugin enabled.
- Attacker crafts an HTTP POST request targeting the AJAX action associated with
implement_user_registration(). - The request includes a malicious
roleparameter set to the 'seller' or 'vendor' role identifier. - The plugin's vulnerable AJAX handler executes, explicitly disabling the Dokan nonce validation filter.
- The plugin invokes
wc_create_new_customer()with the attacker-controlled role parameter. - The WordPress backend registers the new account and the
wc_set_customer_auth_cookie()function is invoked. - The attacker receives an authentication cookie, allowing them to access the site with vendor-level publishing permissions.
Impact
Successful exploitation allows unauthenticated users to gain unauthorized access to 'seller' or 'vendor' accounts on WordPress sites integrated with the Dokan plugin. This provides attackers with publishing capabilities, potentially leading to unauthorized content injection, cross-site scripting (XSS) vectors, or further exploitation of administrative functionality accessible to the vendor role. Any site utilizing Blocksy Companion and Dokan simultaneously is exposed to this risk.
Recommendation
- Upgrade the Blocksy Companion plugin to the latest available version beyond 2.1.58 immediately.
- Monitor server access logs for anomalous
POSTrequests to WordPress AJAX endpoints originating from unauthenticated sessions. - Verify that Dokan vendor registration settings are explicitly managed by administrative policy rather than plugin-level overrides.
Immediate actions
Audit WordPress installations for Blocksy Companion version <= 2.1.58
Mitigations
Upgrade Blocksy Companion to latest version
CVE-2026-107645
Detection coverage 1
Detect CVE-2026-107645 - Blocksy Companion Unauthenticated Registration Attempt
criticalDetects exploitation of CVE-2026-107645 where an unauthenticated session performs a registration action via the Blocksy AJAX handler.
Detection queries are available on the platform. Get full rules →