Overview
Blocksy Companion is the companion plugin for the popular Blocksy WordPress theme, bundling extended customizer options, dynamic-data blocks, and integration hooks with WooCommerce and multi-vendor marketplace plugins. CVE-2026-107645 is a critical, unauthenticated privilege-escalation flaw in that integration layer: the plugin's own user-registration AJAX handler deliberately disables the nonce check that the Dokan multi-vendor marketplace plugin relies on to gate vendor signups, then trusts an attacker-supplied role value when creating the new account. The result is that anyone, with no prior authentication, can register — and be auto-logged in as — a Dokan seller (vendor) account, even on sites where the site owner has explicitly turned vendor registration off in Dokan's own settings. NVD published the record on 2026-10-10 (reserved 2026-10-08) with a CVSS 3.1 score of 9.1 (Critical); the advisory was assigned and tracked by Wordfence under vulnerability ID 7757f41d-c1f1-4df1-8048-b1c78a897548.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-107645 |
| CVSS Score | 9.1 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CWE | CWE-269 (Improper Privilege Management) |
| Attack Vector | Network — no authentication or user interaction required |
| Privileges Required | None |
| User Interaction | None |
| Affected Component | implement_user_registration() AJAX handler (account-auth.php) |
| Affected Versions | Blocksy Companion ≤ 2.1.58 |
| Fixed In | Blocksy Companion 2.1.59 (per the WordPress Plugin SVN/Trac changeset to account-auth.php) |
| Assigner / Source | Wordfence Threat Intelligence — vulnerability ID 7757f41d-c1f1-4df1-8048-b1c78a897548 |
| Discovered By | Not publicly credited in the advisories reviewed at time of writing |
How It Works
Blocksy Companion ships an AJAX-reachable registration handler, implement_user_registration(), that is meant to let visitors sign up for an account. When the Dokan multi-vendor plugin is active, Dokan normally gates its own vendor-registration flow behind a nonce check — a standard WordPress anti-CSRF/anti-abuse control exposed via the dokan_register_nonce_check filter.
The vulnerable handler explicitly disables that control:
add_filter('dokan_register_nonce_check', '__return_false');With Dokan's nonce check forced off, the handler goes on to trust an attacker-controlled $_POST['role'] value, passing it straight into WooCommerce's wc_create_new_customer() to create the account and wc_set_customer_auth_cookie() to immediately log the attacker into it. Because the role parameter is never validated against what the site owner actually permits, an attacker can set it to Dokan's seller (vendor) role — bypassing not just the nonce check but the site's own Dokan configuration, including installations where vendor self-registration has been explicitly disabled. The plugin's internal logic overrides that site-level policy entirely.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | High — a freshly-minted vendor account gains access to the Dokan vendor dashboard and any marketplace data scoped to sellers |
| Integrity | High — the attacker can create/modify product listings and other vendor-scoped content under a legitimate, authenticated account |
| Availability | None — the CVSS vector (A:N) reflects no direct availability impact |
| Authentication Required | None — the AJAX handler is reachable pre-auth |
| User Interaction | None — fully automatable, no victim action needed |
Who Is At Risk
- Any WordPress site running Blocksy Companion ≤ 2.1.58 alongside the Dokan multi-vendor marketplace plugin and WooCommerce
- Multi-vendor marketplaces that believe they have closed off vendor signups via Dokan's own admin settings — this flaw bypasses that control entirely
- Sites where new-vendor approval is assumed to require manual review; this path creates an already-authenticated seller account with no owner awareness
Attack Chain
- Locate the target — Attacker identifies a WordPress site running Blocksy Companion with Dokan and WooCommerce active.
- Send the forged request — Attacker POSTs directly to the plugin's registration AJAX action, with
roleset to Dokan's seller/vendor role, no nonce or prior session required. - Nonce check bypassed — The handler's
add_filter('dokan_register_nonce_check', '__return_false')call suppresses Dokan's own anti-abuse check before registration proceeds. - Account created with attacker-chosen role — The handler passes the unvalidated
rolevalue towc_create_new_customer(), creating a new WooCommerce/Dokan user with vendor privileges. - Auto-authentication —
wc_set_customer_auth_cookie()immediately logs the attacker into the new account — no credentials exchange, no email verification step required. - Operate as a vendor — The attacker now holds a live, authenticated Dokan seller account with publishing capabilities beyond a normal customer, even if the site owner disabled vendor signups.
Mitigation
Immediate Actions
- Upgrade to
Blocksy Companion≥ 2.1.59, which removes the forced nonce-check bypass inaccount-auth.php. - If immediate patching isn't possible, consider blocking or rate-limiting requests to the plugin's registration AJAX action at the WAF/edge layer until the update can be applied.
- Audit existing user accounts for any Dokan seller/vendor registrations that site admins don't recognize or didn't approve.
Detection Opportunities
- Review the
wp_userstable (and Dokan's vendor/seller records) for accounts with the seller role that have no corresponding legitimate application, approval step, or email trail. - Check web server /
admin-ajax.phpaccess logs for POST requests to the registration action carrying unexpectedroleparameter values, especially from unauthenticated sessions. - Wordfence firewall users should confirm their rule set is current — as the reporting CNA, Wordfence is positioned to ship a targeted firewall rule for this exact handler.
Defence-in-Depth
- Keep Blocksy Companion, Dokan, and WooCommerce all current — this bug is specifically in the seam between a theme-companion plugin and a marketplace plugin's own security control, a class of issue that recurs when plugins integrate with each other's APIs.
- Periodically audit vendor/seller account lists on multi-vendor sites regardless of patch status, since a disabled vendor-signup setting should not be the only control relied upon.
- Apply least privilege to the Dokan seller role's capabilities where Dokan's permission model allows it, to limit the blast radius of any account created through this or similar gaps.
Background
Blocksy is one of the more widely installed free/premium WordPress themes, and Blocksy Companion is its plugin half, adding customizer features, dynamic-data blocks, and integration points with WooCommerce and third-party marketplace plugins like Dokan. Dokan itself is a popular WooCommerce extension that turns a WordPress store into an Amazon/Etsy-style marketplace with multiple independent sellers, and it ships its own nonce-based protection around vendor self-registration specifically to let store owners control who can become a seller. CVE-2026-107645 shows what happens when an integration layer reaches into another plugin's security control and turns it off outright: Dokan's own gate becomes irrelevant, and a theme-companion plugin's registration shortcut becomes a full unauthenticated privilege-escalation path. This is one of several Blocksy Companion vulnerabilities disclosed in 2026 — including CVE-2026-97247 (broken access control), CVE-2026-18488 (stored XSS), and CVE-2026-15158 (arbitrary file upload) — suggesting the plugin's integration and extension surfaces warrant continued scrutiny.