PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107645 creativethemeshq CVE debrief

CVE-2026-107645 is a critical vulnerability in the Blocksy Companion plugin for WordPress, allowing unauthenticated privilege escalation to a Dokan 'seller' account. This vulnerability affects versions up to and including 2.1.58. The issue arises from the implement_user_registration() AJAX handler disabling Dokan's vendor-registration nonce check and trusting an attacker-supplied 'role' value. This allows attackers to elevate privileges and auto-authenticate into the seller account, granting publishing capabilities beyond those of a normal customer.

Vendor
creativethemeshq
Product
Blocksy Companion
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for WordPress installations with the Blocksy Companion plugin, particularly those using Dokan vendor signup, should assess exposure and prioritize verification and remediation.

Why it matters

CVE-2026-107645 is a critical vulnerability allowing unauthenticated privilege escalation in the Blocksy Companion plugin for WordPress. Defenders should prioritize verifying exposure, assessing Dokan vendor signup configuration, and monitoring for suspicious activity.

  • Potential for unauthenticated attackers to elevate privileges to a Dokan 'seller' account
  • Possible auto-authentication into the seller account, granting publishing capabilities
  • Need for verification of Blocksy Companion versions and Dokan vendor signup configuration
  • Potential for exploitation requires verification from official sources

Technical summary

The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58. The implement_user_registration() AJAX handler explicitly disables Dokan's vendor-registration nonce check and trusts an attacker-supplied 'role' value when invoking wc_create_new_customer() and wc_set_customer_auth_cookie(). This allows unauthenticated attackers to elevate privileges to a Dokan 'seller' account, potentially leading to auto-authentication and granting publishing capabilities beyond those of a normal customer.

Defensive priority

Defenders should prioritize verifying exposure of Blocksy Companion versions up to 2.1.58 and assessing the impact of potential privilege escalation.

Recommended defensive actions

  • Verify Blocksy Companion version and update to a fixed version if necessary
  • Assess Dokan vendor signup configuration and restrict access if not required
  • Monitor for suspicious account activity and authentication attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to code changes. Defenders should verify Blocksy Companion versions up to 2.1.58 and assess Dokan vendor signup configuration. Evidence limits suggest focusing on official sources and CVE metadata for accurate information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107645 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107645

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107645 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107645

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.