{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-107645", "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599", "state": "PUBLISHED", "assignerShortName": "Wordfence", "dateReserved": "2026-10-08T14:19:54.508Z", "datePublished": "2026-10-10T03:26:44.942Z", "dateUpdated": "2026-10-10T03:26:44.942Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599", "shortName": "Wordfence", "dateUpdated": "2026-10-10T03:26:44.942Z" }, "affected": [ { "vendor": "creativethemeshq", "product": "Blocksy Companion", "versions": [ { "version": "0", "status": "affected", "lessThanOrEqual": "2.1.58", "versionType": "semver" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58 This is due to the implement_user_registration() AJAX handler explicitly disabling Dokan's vendor-registration nonce check (via add_filter('dokan_register_nonce_check', '__return_false')) and then trusting an attacker-supplied $_POST['role'] value when invoking wc_create_new_customer() and wc_set_customer_auth_cookie(). This makes it possible for unauthenticated attackers to elevate their privileges to a Dokan 'seller' (vendor) account — including sites where the Dokan vendor signup is explicitly turned off — and to be auto-authenticated into that account, which grants publishing capabilities beyond those of a normal customer." } ], "title": "Blocksy Companion <= 2.1.58 - Unauthenticated Privilege Escalation to 'role' Parameter", "references": [ { "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7757f41d-c1f1-4df1-8048-b1c78a897548?source=cve" }, { "url": "https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.58/framework/features/account-auth.php#L241" }, { "url": "https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.58/framework/features/account-auth.php#L181" }, { "url": "https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.58/framework/features/account-auth.php#L24" }, { "url": "https://plugins.trac.wordpress.org/changeset/3735192/blocksy-companion/tags/2.1.59/framework/features/account-auth.php?old=3723693&old_path=blocksy-companion%2Ftags%2F2.1.58%2Fframework%2Ffeatures%2Faccount-auth.php" } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "CWE-269 Improper Privilege Management", "cweId": "CWE-269", "type": "CWE" } ] } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "baseScore": 9.1, "baseSeverity": "CRITICAL" } } ], "credits": [ { "lang": "en", "type": "finder", "value": "Sawyer" } ], "timeline": [ { "time": "2026-10-08T14:35:16.000Z", "lang": "en", "value": "Vendor Notified" }, { "time": "2026-10-09T15:15:10.000Z", "lang": "en", "value": "Disclosed" } ] } } }