Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 11 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 10 Oct 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58 This is due to the implement_user_registration() AJAX handler explicitly disabling Dokan's vendor-registration nonce check (via add_filter('dokan_register_nonce_check', '__return_false')) and then trusting an attacker-supplied $_POST['role'] value when invoking wc_create_new_customer() and wc_set_customer_auth_cookie(). This makes it possible for unauthenticated attackers to elevate their privileges to a Dokan 'seller' (vendor) account — including sites where the Dokan vendor signup is explicitly turned off — and to be auto-authenticated into that account, which grants publishing capabilities beyond those of a normal customer. | |
| Title | Blocksy Companion <= 2.1.58 - Unauthenticated Privilege Escalation to 'role' Parameter | |
| Weaknesses | CWE-269 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-10-11T16:55:20.206Z
Reserved: 2026-10-08T14:19:54.508Z
Link: CVE-2026-107645
Updated: 2026-10-11T16:46:27.515Z
Status : Received
Published: 2026-10-10T04:18:10.090
Modified: 2026-10-11T17:17:02.823
Link: CVE-2026-107645
No data.
OpenCVE Enrichment
Updated: 2026-10-10T05:00:15Z