Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-107645

CRITICAL NVD
CVSS Score 9.1
Severity CRITICAL
Published Oct 10, 2026
Vendor unknown

Description

The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58 This is due to the implement_user_registration() AJAX handler explicitly disabling Dokan's vendor-registration nonce check (via add_filter('dokan_register_nonce_check', '__return_false')) and then trusting an attacker-supplied $_POST['role'] value when invoking wc_create_new_customer() and wc_set_customer_auth_cookie(). This makes it possible for unauthenticated attackers to elevate their privileges to a Dokan 'seller' (vendor) account โ€” including sites where the Dokan vendor signup is explicitly turned off โ€” and to be auto-authenticated into that account, which grants publishing capabilities beyond those of a normal customer.

References