CRITICAL 9.1 CVE-2026-107645 Published 10 Oct 2026

Blocksy Companion WordPress Plugin Privilege Escalation Vulnerability

Worried this affects your website?

The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to and including 2.1.58.

The vulnerability lies in the implement_user_registration() AJAX handler, which explicitly disables Dokan's vendor-registration nonce check and then trusts an attacker-supplied $_POST['role'] value when invoking wc_create_new_customer() and wc_set_customer_auth_cookie().

  • Affects versions up to and including 2.1.58.
  • Requires no authentication.
  • Allows unauthenticated attackers to elevate privileges to a Dokan 'seller' (vendor) account.
  • Works even where Dokan vendor signup is explicitly turned off.
  • Auto-authenticates the attacker into the new account, granting publishing capabilities beyond those of a normal customer.

Reference: CVE-2026-107645 on NVD

← Back to Security News