<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:creativethemes:blocksy_companion:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3acreativethemesblocksy_companionwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 05:33:51 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3acreativethemesblocksy_companionwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Privilege Escalation in Blocksy Companion Plugin for WordPress</title><link>https://feed.craftedsignal.io/briefs/2026-10-blocksy-privilege-escalation/</link><pubDate>Sat, 10 Oct 2026 05:33:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-blocksy-privilege-escalation/</guid><description>The Blocksy Companion WordPress plugin is vulnerable to unauthenticated privilege escalation, allowing attackers to create arbitrary vendor accounts by bypassing Dokan registration security checks.</description><content:encoded><![CDATA[<p>The Blocksy Companion plugin for WordPress, in versions up to and including 2.1.58, contains a critical vulnerability (CVE-2026-107645) that enables unauthenticated privilege escalation. The vulnerability resides in the <code>implement_user_registration()</code> AJAX handler, which incorrectly disables the Dokan vendor-registration nonce check by executing <code>add_filter('dokan_register_nonce_check', '__return_false')</code>.</p>
<p>By sending a specially crafted request to this endpoint, an unauthenticated attacker can supply an arbitrary <code>role</code> parameter to <code>wc_create_new_customer()</code> and <code>wc_set_customer_auth_cookie()</code>. This process ignores site-wide settings that may have disabled vendor registration, automatically creating and authenticating a user with 'seller' (vendor) privileges. This grants the attacker elevated publishing capabilities on the affected WordPress site, significantly expanding their control beyond that of a standard customer. Because this exploit operates via the public-facing AJAX handler, it is accessible to any remote, unauthenticated user, representing a high risk for sites running the vulnerable plugin configuration.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target WordPress site running the vulnerable Blocksy Companion plugin (version &lt;= 2.1.58) with the Dokan plugin enabled.</li>
<li>Attacker crafts an HTTP POST request targeting the AJAX action associated with <code>implement_user_registration()</code>.</li>
<li>The request includes a malicious <code>role</code> parameter set to the 'seller' or 'vendor' role identifier.</li>
<li>The plugin's vulnerable AJAX handler executes, explicitly disabling the Dokan nonce validation filter.</li>
<li>The plugin invokes <code>wc_create_new_customer()</code> with the attacker-controlled role parameter.</li>
<li>The WordPress backend registers the new account and the <code>wc_set_customer_auth_cookie()</code> function is invoked.</li>
<li>The attacker receives an authentication cookie, allowing them to access the site with vendor-level publishing permissions.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated users to gain unauthorized access to 'seller' or 'vendor' accounts on WordPress sites integrated with the Dokan plugin. This provides attackers with publishing capabilities, potentially leading to unauthorized content injection, cross-site scripting (XSS) vectors, or further exploitation of administrative functionality accessible to the vendor role. Any site utilizing Blocksy Companion and Dokan simultaneously is exposed to this risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the Blocksy Companion plugin to the latest available version beyond 2.1.58 immediately.</li>
<li>Monitor server access logs for anomalous <code>POST</code> requests to WordPress AJAX endpoints originating from unauthenticated sessions.</li>
<li>Verify that Dokan vendor registration settings are explicitly managed by administrative policy rather than plugin-level overrides.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>wordpress</category><category>privilege-escalation</category><category>web-application</category></item></channel></rss>