External risk intelligence

Blocksy Companion WordPress Plugin Privilege Escalation Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-107645

The vulnerability exists in a WordPress plugin that handles user registration and authentication. Such functionality is inherently designed to be public-facing, allowing unauthenticated users to interact with the site's registration interface, making this service exposed by design in normal deployment.

Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

The Blocksy Companion plugin for WordPress has a critical vulnerability that allows unauthenticated attackers to gain administrative privileges, potentially enabling unauthorized content publishing. This issue impacts how user registration and authentication are handled within the plugin.

  • Unauthenticated users can gain admin privileges.
  • Affects WordPress sites using the plugin.
  • Confirm relevance and exposure for your sites.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a crafted request to the WordPress site, targeting the Blocksy Companion plugin's user registration feature. This allows them to bypass security checks and register as a seller (vendor) account, even if vendor registration is disabled. Once registered, they are automatically logged in with the privileges of a seller, gaining the ability to publish content.

  • No authentication required.
  • Triggers registration handler.
  • Grants seller privileges and publishing ability.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could potentially gain elevated privileges as a Dokan seller, even on sites where vendor signup is disabled. This could allow them to publish content or perform actions normally reserved for sellers.

  • Seller account privileges at risk.
  • Exploits registration and authentication flaws.
  • Unauthorized content publishing may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Blocksy Companion plugin's privilege escalation vulnerability primarily impacts WordPress site administrators and platform owners responsible for managing plugins and user roles. The first critical step is to identify all WordPress instances using the affected plugin, determine their business criticality, and confirm which team or individual is accountable for their maintenance and security.

  • WordPress site owners.
  • Verify plugin and user role configurations.
  • Plan and coordinate updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Blocksy Companion plugin?

Blocksy Companion is a supplemental plugin for the Blocksy WordPress theme. It extends the theme's functionality by adding features for site customization, header and footer building, and integration with third-party tools like the Dokan multivendor marketplace plugin to manage user roles and account authentication.

What does CVE-2026-107645 mean?

This CVE describes a privilege escalation flaw classified as CWE-269 (Improper Privilege Management). It occurs when the plugin's registration code incorrectly disables security checks and trusts input from an unauthenticated user to assign account roles, effectively allowing a visitor to grant themselves higher permissions than they should possess.

How is this vulnerability triggered?

An attacker triggers this by sending a specifically crafted request to the plugin's AJAX registration handler. Simply browsing the site or performing standard user tasks does not trigger the bug; the attacker must intentionally submit a request that bypasses the expected security nonces to manipulate the user registration process.

Do I need to worry if my site is internal?

Halo Surface Signal indicates this plugin handles public-facing user registration, making it exposed by design in standard setups. While internal sites face less risk from the open internet, the vulnerability allows unauthorized access regardless of network perimeter, so any installation using this plugin's registration feature should be treated as a concern.

When should I prioritize this for my WordPress site?

You should prioritize this immediately if you use Blocksy Companion. Begin by identifying all instances of the plugin across your environment. Coordinate with the teams responsible for these sites to confirm the version in use and prepare for necessary updates to ensure that unauthorized account creation and privilege escalation are blocked.

References