« Volver al listado

CVE-2026-107645

Estado: RecibidaCrítica (9.1)—

El plugin Blocksy Companion para WordPress es vulnerable a escalada de privilegios en versiones hasta la 2.1.58 inclusive. Esto se debe a que el manejador AJAX implement_user_registration() desactiva explícitamente la comprobación de nonce de registro de proveedores de Dokan (a través de add_filter('dokan_register_nonce_check', '__return_false')) y luego confía en un valor $_POST['role'] suministrado por el atacante cuando invoca a wc_create_new_customer() y wc_set_customer_auth_cookie().

Leer descripción completaMostrar menos

Esto hace posible que atacantes no autenticados eleven sus privilegios a una cuenta Dokan 'seller' (proveedor) — incluso en sitios donde el registro de proveedores de Dokan está explícitamente desactivado — y sean autenticados automáticamente en esa cuenta, lo que otorga capacidades de publicación más allá de las de un cliente normal.

Traducción automática del texto original de NVD (en inglés).

CVSS

Probabilidad de explotación (EPSS)

FIRST aún no ha puntuado esta CVE (habitual en CVEs muy recientes o rechazadas).

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad CVSS:3.1/AV:N/AC:L/PR:N/UI:N (red sin autenticación) en handler AJAX de WordPress que permite escalada a cuenta 'seller' con cookies de sesión. CWE-269: improper access control sobre $_POST['role'].

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-107645",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "security@wordfence.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@wordfence.com",
      "affectedData": [
        {
          "vendor": "creativethemeshq",
          "product": "Blocksy Companion",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "2.1.58"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-10-10T04:18:10.090",
  "references": [
    {
      "url": "https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.58/framework/features/account-auth.php#L181",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.58/framework/features/account-auth.php#L24",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.58/framework/features/account-auth.php#L241",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://plugins.trac.wordpress.org/changeset/3735192/blocksy-companion/tags/2.1.59/framework/features/account-auth.php?old=3723693&old_path=blocksy-companion%2Ftags%2F2.1.58%2Fframework%2Ffeatures%2Faccount-auth.php",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7757f41d-c1f1-4df1-8048-b1c78a897548?source=cve",
      "source": "security@wordfence.com"
    }
  ],
  "vulnStatus": "Received",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "security@wordfence.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58 This is due to the implement_user_registration() AJAX handler explicitly disabling Dokan's vendor-registration nonce check (via add_filter('dokan_register_nonce_check', '__return_false')) and then trusting an attacker-supplied $_POST['role'] value when invoking wc_create_new_customer() and wc_set_customer_auth_cookie(). This makes it possible for unauthenticated attackers to elevate their privileges to a Dokan 'seller' (vendor) account — including sites where the Dokan vendor signup is explicitly turned off — and to be auto-authenticated into that account, which grants publishing capabilities beyond those of a normal customer."
    }
  ],
  "lastModified": "2026-10-10T04:18:10.090",
  "sourceIdentifier": "security@wordfence.com"
}