Skip to content
LatestBlock Object Injection in Booklovers Theme by Verifying Version Before 2.13.1
Vulnerabilities

Patch Blocksy Companion Now to Stop Unauthenticated Vendor Account Creation

An unauthenticated privilege escalation flaw in Blocksy Companion versions up to 2.1.58 allows attackers to bypass security checks and create seller accounts.

Patch Blocksy Companion Now to Stop Unauthenticated Vendor Account Creation
Illustration: Vector Update

Key points

  • CVE-2026-107645 affects Blocksy Companion plugin versions 2.1.58 and earlier on WordPress sites.
  • Attackers can bypass nonce checks to create authenticated Dokan seller accounts without logging in.
  • The flaw grants elevated publishing privileges even when vendor registration is disabled by the admin.

System administrators must update the Blocksy Companion plugin immediately to address a critical privilege escalation vulnerability identified as CVE-2026-107645. According to the National Vulnerability Database, versions up to and including 2.1.58 contain a flaw that allows unauthenticated attackers to create seller accounts. This issue carries a CVSS score of 9.1, rating it as critical severity.

In plain English

The vulnerability exists because the plugin’s user registration process ignores standard security tokens. The `implement_user_registration()` AJAX handler disables the nonce check for Dokan vendor registration. It then trusts a role value supplied directly by the attacker in a POST request. This allows anyone on the internet to register as a vendor without permission.

Attackers can force the system to create a new customer and set an authentication cookie automatically. This grants the attacker immediate access to a seller account. They gain publishing capabilities that normal customers do not have. This happens even if the site administrator has explicitly turned off vendor signups.

The background

The flaw involves specific WordPress functions used for customer creation. The plugin invokes `wc_create_new_customer()` and `wc_set_customer_auth_cookie()` using data controlled by the attacker. By using the `add_filter` function to return false for the nonce check, the plugin removes a key layer of protection. This CWE-269 error allows unauthorized privilege escalation.

The affected component is the Blocksy Companion plugin developed by creativethemeshq. The issue is present in all versions up to 2.1.58. Sites using the Dokan multi-vendor marketplace plugin are particularly at risk because the flaw specifically targets vendor registration logic. The attacker does not need an existing account to exploit this.

What changes now

Administrators need to verify their current plugin version immediately. If the site runs Blocksy Companion version 2.1.58 or older, it is vulnerable. The National Vulnerability Database confirms the issue affects these specific versions. No other plugins are mentioned in this report, but the impact is severe for WordPress sites using this specific companion tool.

The ability to create authenticated seller accounts remotely is a significant security risk. Attackers can publish content or manipulate store settings once inside. The auto-authentication feature means the attacker is logged in instantly after registration. This bypasses any login page protections or two-factor authentication that might be in place for manual logins.

Background: Privilege escalation attacks

Privilege escalation is the act of exploiting a bug, design flaw, or configuration oversight to gain elevated access to applications or data. Attackers use these techniques to move from a limited user account to an administrator or root level, allowing them to install malware, steal data, or persist within your environment.

Read the full guide: Privilege Escalation Attacks: How Attackers Steal Control

What to do and how to stay safe: Blocksy Companion

  • Check the version of the Blocksy Companion plugin on all managed WordPress sites to see if it is 2.1.58 or lower.
  • Review user logs for any new vendor or seller accounts created by unknown IP addresses or unusual patterns.
  • Restrict access to the WordPress admin area and AJAX endpoints using firewall rules until the plugin is updated.
  • Monitor the vendor’s official channel for a patched version and apply the update as soon as it becomes available.

Step-by-step guide: Risk-Based Vulnerability Management: Benefits, Limits, and Reality

General security guidance from the Vector Update newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What is CVE-2026-107645?

It is a critical privilege escalation vulnerability in the Blocksy Companion WordPress plugin that allows unauthenticated users to create seller accounts.

Which versions of Blocksy Companion are affected?

All versions up to and including 2.1.58 are vulnerable to this flaw, according to the NVD record.

Can attackers exploit this if vendor registration is disabled?

Yes, the vulnerability allows attackers to create seller accounts even when the site administrator has explicitly turned off vendor signups.

Sources

  1. CVE Program
  2. NVD
Blocksy CompanionWordPressCVE-2026-107645Privilege Escalationcreativethemeshq

Related stories