Impact
The Blocksy Companion plugin for WordPress contains a flaw in the AJAX handler that processes user registration. This flaw selectively disables Dokan’s nonce verification and then accepts an attacker‑supplied role value when creating a new customer and setting the authentication cookie. As a result, anyone able to reach the endpoint can create a Dokan “seller” account without authenticating and be logged in as that account, gaining publishing rights normally reserved for a vendor. The vulnerability consequently allows an unauthenticated user to elevate privileges to a vendor level and to perform actions beyond the scope of a standard customer.
Affected Systems
Affected systems include WordPress sites that have installed creativethemeshq’s Blocksy Companion plugin versions 2.1.58 or older. The issue is specific to that plugin and any site that uses Dokan for vendor management where the plugin is present.
Risk and Exploitability
The CVSS score of 9.1 places this flaw in the high severity range. No EPSS value is available, and it has not been listed in CISA’s KEV catalog, but the attack vector is remote and unauthenticated: an off‑site attacker can trigger the vulnerable AJAX endpoint via HTTP requests. The lack of a nonce check removes a critical guard, so successful exploitation is likely if the site surface area is exposed and the plugin is present.
OpenCVE Enrichment