Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107645— Blocksy Companion <= 2.1.58 - Unauthenticated Privilege Escalation to 'role' Parameter

Quick assessment

Affected
creativethemeshq Blocksy Companion
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 Blocksy Companion 插件在 2.1.58 及以下版本中存在权限提升漏洞。该漏洞源于 AJAX 处理器显式禁用了 Dokan 的 vendor 注册 nonce 验证(通过添加过滤器 ),随后在处理过程中盲目信任攻击者提供的 参数值,并将其传递给 和 函数。 这使得未认证的攻击者能够将自身权限提升至 Dokan 的“卖家”(vendor)账户级别——即使站点明确关闭了 Dokan 卖家注册功能,该漏洞依然有效。攻击者一旦完成权限提升,即可自动登录该卖家账户,从而获得超出普通客户

CVSS 9.1 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107645

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Blocksy Companion <= 2.1.58 - Unauthenticated Privilege Escalation to 'role' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58 This is due to the implement_user_registration() AJAX handler explicitly disabling Dokan's vendor-registration nonce check (via add_filter('dokan_register_nonce_check', '__return_false')) and then trusting an attacker-supplied $_POST['role'] value when invoking wc_create_new_customer() and wc_set_customer_auth_cookie(). This makes it possible for unauthenticated attackers to elevate their privileges to a Dokan 'seller' (vendor) account — including sites where the Dokan vendor signup is explicitly turned off — and to be auto-authenticated into that account, which grants publishing capabilities beyond those of a normal customer.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
creativethemeshq Blocksy Companion 0 ~ 2.1.58 -

II. Public POCs for CVE-2026-107645

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107645

请登录查看更多情报信息。

Other References for CVE-2026-107645 (5)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107645

No comments yet


Leave a comment