SECURITYCRITICALCVE-2026-107645

CVE-2026-107645: Blocksy Companion Disables Dokan's Nonce Check for Unauthenticated Vendor Takeover

An AJAX handler in Blocksy Companion disables Dokan's nonce check, letting unauthenticated attackers auto-register as a vendor (CVSS 9.1).

Dylan H.

Security Team

October 10, 2026
6 min read
CVE-2026-107645: Blocksy Companion Disables Dokan's Nonce Check for Unauthenticated Vendor Takeover

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • creativethemeshq/blocksy-companion — Blocksy Companion ≤ 2.1.58

Overview

Blocksy Companion is the companion plugin for the popular Blocksy WordPress theme, bundling extended customizer options, dynamic-data blocks, and integration hooks with WooCommerce and multi-vendor marketplace plugins. CVE-2026-107645 is a critical, unauthenticated privilege-escalation flaw in that integration layer: the plugin's own user-registration AJAX handler deliberately disables the nonce check that the Dokan multi-vendor marketplace plugin relies on to gate vendor signups, then trusts an attacker-supplied role value when creating the new account. The result is that anyone, with no prior authentication, can register — and be auto-logged in as — a Dokan seller (vendor) account, even on sites where the site owner has explicitly turned vendor registration off in Dokan's own settings. NVD published the record on 2026-10-10 (reserved 2026-10-08) with a CVSS 3.1 score of 9.1 (Critical); the advisory was assigned and tracked by Wordfence under vulnerability ID 7757f41d-c1f1-4df1-8048-b1c78a897548.


Technical Details

FieldValue
CVE IDCVE-2026-107645
CVSS Score9.1 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWECWE-269 (Improper Privilege Management)
Attack VectorNetwork — no authentication or user interaction required
Privileges RequiredNone
User InteractionNone
Affected Componentimplement_user_registration() AJAX handler (account-auth.php)
Affected VersionsBlocksy Companion ≤ 2.1.58
Fixed InBlocksy Companion 2.1.59 (per the WordPress Plugin SVN/Trac changeset to account-auth.php)
Assigner / SourceWordfence Threat Intelligence — vulnerability ID 7757f41d-c1f1-4df1-8048-b1c78a897548
Discovered ByNot publicly credited in the advisories reviewed at time of writing

How It Works

Blocksy Companion ships an AJAX-reachable registration handler, implement_user_registration(), that is meant to let visitors sign up for an account. When the Dokan multi-vendor plugin is active, Dokan normally gates its own vendor-registration flow behind a nonce check — a standard WordPress anti-CSRF/anti-abuse control exposed via the dokan_register_nonce_check filter.

The vulnerable handler explicitly disables that control:

add_filter('dokan_register_nonce_check', '__return_false');

With Dokan's nonce check forced off, the handler goes on to trust an attacker-controlled $_POST['role'] value, passing it straight into WooCommerce's wc_create_new_customer() to create the account and wc_set_customer_auth_cookie() to immediately log the attacker into it. Because the role parameter is never validated against what the site owner actually permits, an attacker can set it to Dokan's seller (vendor) role — bypassing not just the nonce check but the site's own Dokan configuration, including installations where vendor self-registration has been explicitly disabled. The plugin's internal logic overrides that site-level policy entirely.


Impact Assessment

Impact AreaDescription
ConfidentialityHigh — a freshly-minted vendor account gains access to the Dokan vendor dashboard and any marketplace data scoped to sellers
IntegrityHigh — the attacker can create/modify product listings and other vendor-scoped content under a legitimate, authenticated account
AvailabilityNone — the CVSS vector (A:N) reflects no direct availability impact
Authentication RequiredNone — the AJAX handler is reachable pre-auth
User InteractionNone — fully automatable, no victim action needed

Who Is At Risk

  • Any WordPress site running Blocksy Companion ≤ 2.1.58 alongside the Dokan multi-vendor marketplace plugin and WooCommerce
  • Multi-vendor marketplaces that believe they have closed off vendor signups via Dokan's own admin settings — this flaw bypasses that control entirely
  • Sites where new-vendor approval is assumed to require manual review; this path creates an already-authenticated seller account with no owner awareness

Attack Chain

  1. Locate the target — Attacker identifies a WordPress site running Blocksy Companion with Dokan and WooCommerce active.
  2. Send the forged request — Attacker POSTs directly to the plugin's registration AJAX action, with role set to Dokan's seller/vendor role, no nonce or prior session required.
  3. Nonce check bypassed — The handler's add_filter('dokan_register_nonce_check', '__return_false') call suppresses Dokan's own anti-abuse check before registration proceeds.
  4. Account created with attacker-chosen role — The handler passes the unvalidated role value to wc_create_new_customer(), creating a new WooCommerce/Dokan user with vendor privileges.
  5. Auto-authentication — wc_set_customer_auth_cookie() immediately logs the attacker into the new account — no credentials exchange, no email verification step required.
  6. Operate as a vendor — The attacker now holds a live, authenticated Dokan seller account with publishing capabilities beyond a normal customer, even if the site owner disabled vendor signups.

Mitigation

Immediate Actions

  • Upgrade to Blocksy Companion ≥ 2.1.59, which removes the forced nonce-check bypass in account-auth.php.
  • If immediate patching isn't possible, consider blocking or rate-limiting requests to the plugin's registration AJAX action at the WAF/edge layer until the update can be applied.
  • Audit existing user accounts for any Dokan seller/vendor registrations that site admins don't recognize or didn't approve.

Detection Opportunities

  • Review the wp_users table (and Dokan's vendor/seller records) for accounts with the seller role that have no corresponding legitimate application, approval step, or email trail.
  • Check web server / admin-ajax.php access logs for POST requests to the registration action carrying unexpected role parameter values, especially from unauthenticated sessions.
  • Wordfence firewall users should confirm their rule set is current — as the reporting CNA, Wordfence is positioned to ship a targeted firewall rule for this exact handler.

Defence-in-Depth

  • Keep Blocksy Companion, Dokan, and WooCommerce all current — this bug is specifically in the seam between a theme-companion plugin and a marketplace plugin's own security control, a class of issue that recurs when plugins integrate with each other's APIs.
  • Periodically audit vendor/seller account lists on multi-vendor sites regardless of patch status, since a disabled vendor-signup setting should not be the only control relied upon.
  • Apply least privilege to the Dokan seller role's capabilities where Dokan's permission model allows it, to limit the blast radius of any account created through this or similar gaps.

Background

Blocksy is one of the more widely installed free/premium WordPress themes, and Blocksy Companion is its plugin half, adding customizer features, dynamic-data blocks, and integration points with WooCommerce and third-party marketplace plugins like Dokan. Dokan itself is a popular WooCommerce extension that turns a WordPress store into an Amazon/Etsy-style marketplace with multiple independent sellers, and it ships its own nonce-based protection around vendor self-registration specifically to let store owners control who can become a seller. CVE-2026-107645 shows what happens when an integration layer reaches into another plugin's security control and turns it off outright: Dokan's own gate becomes irrelevant, and a theme-companion plugin's registration shortcut becomes a full unauthenticated privilege-escalation path. This is one of several Blocksy Companion vulnerabilities disclosed in 2026 — including CVE-2026-97247 (broken access control), CVE-2026-18488 (stored XSS), and CVE-2026-15158 (arbitrary file upload) — suggesting the plugin's integration and extension surfaces warrant continued scrutiny.


References