
Key points
- CVE-2026-107645 affects Blocksy Companion versions up to and including 2.1.58.
- Unauthenticated attackers can elevate privileges to Dokan vendor accounts.
- The flaw bypasses nonce checks even when vendor signup is disabled.
The Blocksy Companion plugin for WordPress contains a critical privilege escalation vulnerability in versions up to and including 2.1.58, according to the National Vulnerability Database. This flaw, tracked as CVE-2026-107645, allows unauthenticated attackers to create vendor accounts and gain elevated access to site functions without providing valid credentials.
The vulnerability stems from the implement_user_registration() AJAX handler, which explicitly disables Dokan’s vendor-registration nonce check by adding a filter that returns false. The handler then trusts an attacker-supplied role value from the POST request when invoking wc_create_new_customer() and wc_set_customer_auth_cookie(). This logic error grants immediate auto-authentication into the newly created high-privilege account.
Technical Context and Risk
Security researchers classify this issue under CWE-269, improper privilege management. The National Vulnerability Database assigns a CVSS score of 9.1, rating the severity as critical. Attackers can elevate their privileges to a Dokan seller account, which provides publishing capabilities beyond those of a standard customer. This occurs even on sites where administrators have explicitly turned off vendor signup features, rendering that configuration ineffective against this specific exploit.
Affected Systems and Scope
The flaw impacts WordPress installations running the Blocksy Companion plugin by creativethemeshq. Any version up to and including 2.1.58 is affected. Organisations using the Dokan multivendor marketplace plugin alongside Blocksy Companion are at particular risk, as the vulnerability directly interacts with Dokan’s registration mechanisms. Sites that rely on disabling vendor signup to control access remain vulnerable because the exploit bypasses those settings entirely.
What happens next
No patch or fix has been confirmed yet by the vendor. Administrators should monitor official channels from creativethemeshq for an updated version of the plugin. Until a fix is available, sites may need to restrict access to the affected AJAX endpoints or temporarily disable the plugin if business operations allow. Security teams should review logs for unusual account creation patterns indicative of exploitation.
What to do and how to stay safe: Blocksy Companion
- Audit WordPress plugins to identify if Blocksy Companion version 2.1.58 or earlier is installed.
- Monitor server logs for unauthenticated requests attempting to create vendor or seller accounts.
- Restrict access to AJAX endpoints used for user registration where possible.
- Prepare to apply updates immediately once the vendor releases a patched version.
Step-by-step guide: Vulnerability Scanning for Small Teams: Practical Steps and Limits
General security guidance from the Payload Report newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What is CVE-2026-107645?
It is a critical privilege escalation vulnerability in the Blocksy Companion WordPress plugin that allows unauthenticated users to create vendor accounts.
Which versions of Blocksy Companion are affected?
All versions up to and including 2.1.58 are vulnerable to this flaw.
Can attackers exploit this if vendor signup is disabled?
Yes, the vulnerability bypasses nonce checks and allows account creation even when vendor signup is explicitly turned off.



