PatchSiren cyber security CVE debrief
CVE-2026-107645 creativethemeshq CVE debrief
CVE-2026-107645 is a critical vulnerability in the Blocksy Companion plugin for WordPress, allowing unauthenticated privilege escalation to a Dokan 'seller' account. This vulnerability affects versions up to and including 2.1.58. The issue arises from the implement_user_registration() AJAX handler disabling Dokan's vendor-registration nonce check and trusting an attacker-supplied 'role' value. This allows attackers to elevate privileges and auto-authenticate into the seller account, granting publishing capabilities beyond those of a normal customer.
- Vendor
- creativethemeshq
- Product
- Blocksy Companion
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations with the Blocksy Companion plugin, particularly those using Dokan vendor signup, should assess exposure and prioritize verification and remediation.
Why it matters
CVE-2026-107645 is a critical vulnerability allowing unauthenticated privilege escalation in the Blocksy Companion plugin for WordPress. Defenders should prioritize verifying exposure, assessing Dokan vendor signup configuration, and monitoring for suspicious activity.
- Potential for unauthenticated attackers to elevate privileges to a Dokan 'seller' account
- Possible auto-authentication into the seller account, granting publishing capabilities
- Need for verification of Blocksy Companion versions and Dokan vendor signup configuration
- Potential for exploitation requires verification from official sources
Technical summary
The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58. The implement_user_registration() AJAX handler explicitly disables Dokan's vendor-registration nonce check and trusts an attacker-supplied 'role' value when invoking wc_create_new_customer() and wc_set_customer_auth_cookie(). This allows unauthenticated attackers to elevate privileges to a Dokan 'seller' account, potentially leading to auto-authentication and granting publishing capabilities beyond those of a normal customer.
Defensive priority
Defenders should prioritize verifying exposure of Blocksy Companion versions up to 2.1.58 and assessing the impact of potential privilege escalation.
Recommended defensive actions
- Verify Blocksy Companion version and update to a fixed version if necessary
- Assess Dokan vendor signup configuration and restrict access if not required
- Monitor for suspicious account activity and authentication attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to code changes. Defenders should verify Blocksy Companion versions up to 2.1.58 and assess Dokan vendor signup configuration. Evidence limits suggest focusing on official sources and CVE metadata for accurate information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107645 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107645
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107645 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107645
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Blocksy Companion <= 2.1.58 - Unauthenticated Privilege Escalation to 'role' Parameter
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107645.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.58/framework/features/account-auth.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.