{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acreativethemesblocksy_companionwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:creativethemes:blocksy_companion:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-107645"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Blocksy Companion (\u003c= 2.1.58)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","privilege-escalation","web-application"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Blocksy Companion plugin for WordPress, in versions up to and including 2.1.58, contains a critical vulnerability (CVE-2026-107645) that enables unauthenticated privilege escalation. The vulnerability resides in the \u003ccode\u003eimplement_user_registration()\u003c/code\u003e AJAX handler, which incorrectly disables the Dokan vendor-registration nonce check by executing \u003ccode\u003eadd_filter('dokan_register_nonce_check', '__return_false')\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eBy sending a specially crafted request to this endpoint, an unauthenticated attacker can supply an arbitrary \u003ccode\u003erole\u003c/code\u003e parameter to \u003ccode\u003ewc_create_new_customer()\u003c/code\u003e and \u003ccode\u003ewc_set_customer_auth_cookie()\u003c/code\u003e. This process ignores site-wide settings that may have disabled vendor registration, automatically creating and authenticating a user with 'seller' (vendor) privileges. This grants the attacker elevated publishing capabilities on the affected WordPress site, significantly expanding their control beyond that of a standard customer. Because this exploit operates via the public-facing AJAX handler, it is accessible to any remote, unauthenticated user, representing a high risk for sites running the vulnerable plugin configuration.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target WordPress site running the vulnerable Blocksy Companion plugin (version \u0026lt;= 2.1.58) with the Dokan plugin enabled.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the AJAX action associated with \u003ccode\u003eimplement_user_registration()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe request includes a malicious \u003ccode\u003erole\u003c/code\u003e parameter set to the 'seller' or 'vendor' role identifier.\u003c/li\u003e\n\u003cli\u003eThe plugin's vulnerable AJAX handler executes, explicitly disabling the Dokan nonce validation filter.\u003c/li\u003e\n\u003cli\u003eThe plugin invokes \u003ccode\u003ewc_create_new_customer()\u003c/code\u003e with the attacker-controlled role parameter.\u003c/li\u003e\n\u003cli\u003eThe WordPress backend registers the new account and the \u003ccode\u003ewc_set_customer_auth_cookie()\u003c/code\u003e function is invoked.\u003c/li\u003e\n\u003cli\u003eThe attacker receives an authentication cookie, allowing them to access the site with vendor-level publishing permissions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated users to gain unauthorized access to 'seller' or 'vendor' accounts on WordPress sites integrated with the Dokan plugin. This provides attackers with publishing capabilities, potentially leading to unauthorized content injection, cross-site scripting (XSS) vectors, or further exploitation of administrative functionality accessible to the vendor role. Any site utilizing Blocksy Companion and Dokan simultaneously is exposed to this risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Blocksy Companion plugin to the latest available version beyond 2.1.58 immediately.\u003c/li\u003e\n\u003cli\u003eMonitor server access logs for anomalous \u003ccode\u003ePOST\u003c/code\u003e requests to WordPress AJAX endpoints originating from unauthenticated sessions.\u003c/li\u003e\n\u003cli\u003eVerify that Dokan vendor registration settings are explicitly managed by administrative policy rather than plugin-level overrides.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T05:33:51Z","date_published":"2026-10-10T05:33:51Z","id":"https://feed.craftedsignal.io/briefs/2026-10-blocksy-privilege-escalation/","summary":"The Blocksy Companion WordPress plugin is vulnerable to unauthenticated privilege escalation, allowing attackers to create arbitrary vendor accounts by bypassing Dokan registration security checks.","title":"Unauthenticated Privilege Escalation in Blocksy Companion Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-10-blocksy-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:creativethemes:blocksy_companion:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}